Input validation error in Apache CloudStack - CVE-2026-50112
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands as root on the KVM hypervisor host.
The vulnerability exists due to improper input validation in direct download, metalink, and NFS template handling when processing template registrations that reference crafted metalink files and inner URLs that are not re-validated. A remote user can register a crafted template to execute arbitrary shell commands as root on the KVM hypervisor host.
The issue is reachable via the public CloudStack API and can affect hosts running other tenants' virtual machines.