Improper access control in Apache CloudStack - CVE-2026-59655
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose OAuth provider client secrets.
The vulnerability exists due to improper access control in the OAuth authentication plugin when listing OAuth providers. A remote attacker can invoke provider listing functionality to disclose OAuth provider client secrets.
The issue is described as unauthenticated client-secret disclosure.