Information disclosure in Apache CloudStack - CVE-2026-61397
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose OAuth2 tokens across requests.
The vulnerability exists due to exposure of sensitive information in the OAuth2 authentication plugin and Google OAuth integration when handling OAuth2 requests. A remote attacker can exploit cross-request token leakage to disclose OAuth2 tokens across requests.