Missing Authorization in Apache CloudStack - CVE-2026-66721
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose host tags outside the intended domain scope.
The vulnerability exists due to missing authorization in the listHostTags API when domain admins request host tag listings without domain scoping. A remote user can call the API to disclose host tags outside the intended domain scope.
By default, Domain Admins have permission to call the API.