Improper access control in Apache CloudStack - CVE-2026-50222

 

Improper access control in Apache CloudStack - CVE-2026-50222

Published: August 24, 2026


Vulnerability identifier: #VU144646
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50222
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access and manipulate userdata resources across tenants.

The vulnerability exists due to improper access control in the userdata reference APIs and deleteCniConfiguration API when handling requests for userdata resources without sufficient access validation. A remote user can send crafted API requests to access and manipulate userdata resources across tenants.

The affected APIs include deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine.


Affected software

Apache CloudStack

How to mitigate CVE-2026-50222

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins