Improper access control in Apache CloudStack - CVE-2026-25199

 

Improper access control in Apache CloudStack - CVE-2026-25199

Published: May 12, 2026


Vulnerability identifier: #VU131156
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25199
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain full control over another account's virtual machine.

The vulnerability exists due to improper access control in the Proxmox extension when using the user-editable proxmox_vmid instance setting to associate CloudStack instances with Proxmox virtual machines. A remote user can modify the setting to reference a virtual machine belonging to another account to gain full control over another account's virtual machine.

Proxmox VM IDs are predictable, which helps exploitation.


Affected software

Apache CloudStack

How to mitigate CVE-2026-25199

Install security update from vendor's website.

Apache CloudStack - update to 4.22.0.1

External References

Related Security Bulletins