Improper access control in Apache CloudStack - CVE-2026-25199
Published: May 12, 2026
Apache CloudStack
Detailed vulnerability description
The vulnerability allows a remote user to gain full control over another account's virtual machine.
The vulnerability exists due to improper access control in the Proxmox extension when using the user-editable proxmox_vmid instance setting to associate CloudStack instances with Proxmox virtual machines. A remote user can modify the setting to reference a virtual machine belonging to another account to gain full control over another account's virtual machine.
Proxmox VM IDs are predictable, which helps exploitation.