Cross-site scripting in Apache CloudStack - CVE-2026-61398
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the UI instance reset password functionality when rendering insufficiently escaped output. A remote attacker can inject crafted content to execute arbitrary script in the victim's browser.