Improper privilege management in Apache CloudStack - CVE-2026-59799
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to bypass the two-factor authentication disable flow.
The vulnerability exists due to improper privilege management in the two-factor authentication plugin when handling requests to disable two-factor authentication. A remote user can exploit missing privilege checks to bypass the two-factor authentication disable flow.