Improper access control in Apache CloudStack - CVE-2026-66797
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to create and read annotations on entities they do not own.
The vulnerability exists due to improper access control in the addAnnotation and listAnnotation APIs when processing entity UUIDs and incorrectly honoring ownership check results. A remote user can supply a target entity UUID to create and read annotations on entities they do not own.