OS Command Injection in Apache CloudStack - CVE-2026-47359

 

OS Command Injection in Apache CloudStack - CVE-2026-47359

Published: August 24, 2026


Vulnerability identifier: #VU144644
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47359
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the KVM hypervisor host.

The vulnerability exists due to command injection in the NAS backup provider plugin addBackupRepository and updateBackupRepository APIs when processing unsanitized backup repository mount command options. A remote user can supply crafted command options to execute arbitrary commands on the KVM hypervisor host.

Exploitation requires an operator account, and the injected commands are triggered when a backup restore is later performed.


Affected software

Apache CloudStack

How to mitigate CVE-2026-47359

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins