Missing Authorization in Apache CloudStack - CVE-2026-66721

 

Missing Authorization in Apache CloudStack - CVE-2026-66721

Published: August 24, 2026


Vulnerability identifier: #VU144659
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66721
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose host tags outside the intended domain scope.

The vulnerability exists due to missing authorization in the listHostTags API when domain admins request host tag listings without domain scoping. A remote user can call the API to disclose host tags outside the intended domain scope.

By default, Domain Admins have permission to call the API.


Affected software

Apache CloudStack

How to mitigate CVE-2026-66721

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins