Improper access control in Apache CloudStack - CVE-2026-59780
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose LDAP provider configuration information.
The vulnerability exists due to improper access control in the LDAP authentication plugin listLdapConfigurations API when listing LDAP providers. A remote user can invoke the API to disclose LDAP provider configuration information.
By default, the API is available to all default roles.