OS Command Injection in Apache CloudStack - CVE-2026-47359
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on the KVM hypervisor host.
The vulnerability exists due to command injection in the NAS backup provider plugin addBackupRepository and updateBackupRepository APIs when processing unsanitized backup repository mount command options. A remote user can supply crafted command options to execute arbitrary commands on the KVM hypervisor host.
Exploitation requires an operator account, and the injected commands are triggered when a backup restore is later performed.