Command injection in Apache CloudStack - CVE-2026-61400
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on system VMs and virtual routers.
The vulnerability exists due to command injection in the getDiagnosticsData and runDiagnostics functionality when processing diagnostic command input. A remote user can send crafted diagnostic requests to execute arbitrary commands on system VMs and virtual routers.
The commands run as root, or at minimum as the diagnostics-process user, and the affected APIs are restricted to Admin role accounts by default.