Improper access control in Apache CloudStack - CVE-2026-66797

 

Improper access control in Apache CloudStack - CVE-2026-66797

Published: August 24, 2026


Vulnerability identifier: #VU144661
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66797
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create and read annotations on entities they do not own.

The vulnerability exists due to improper access control in the addAnnotation and listAnnotation APIs when processing entity UUIDs and incorrectly honoring ownership check results. A remote user can supply a target entity UUID to create and read annotations on entities they do not own.


Affected software

Apache CloudStack

How to mitigate CVE-2026-66797

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins