Improper access control in Apache CloudStack - CVE-2026-65613
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose webhook delivery information and delete deliveries without authorization.
The vulnerability exists due to improper access control in the webhook module when listing and deleting deliveries. A remote user can invoke delivery management functionality to disclose webhook delivery information and delete deliveries without authorization.