Input validation error in Apache CloudStack - CVE-2026-50112

 

Input validation error in Apache CloudStack - CVE-2026-50112

Published: August 24, 2026


Vulnerability identifier: #VU144645
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50112
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands as root on the KVM hypervisor host.

The vulnerability exists due to improper input validation in direct download, metalink, and NFS template handling when processing template registrations that reference crafted metalink files and inner URLs that are not re-validated. A remote user can register a crafted template to execute arbitrary shell commands as root on the KVM hypervisor host.

The issue is reachable via the public CloudStack API and can affect hosts running other tenants' virtual machines.


Affected software

Apache CloudStack

How to mitigate CVE-2026-50112

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins