Improper Certificate Validation in Apache CloudStack - CVE-2026-68745

 

Improper Certificate Validation in Apache CloudStack - CVE-2026-68745

Published: August 24, 2026


Vulnerability identifier: #VU144662
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68745
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to forge SAML responses and log in to the management server.

The vulnerability exists due to improper certificate validation in SAML authentication when processing SAML responses from a certificate-less identity provider configuration. A remote attacker can spoof the identity provider address or use a registered URL under their control to forge SAML responses and log in to the management server.

The issue affects SAML authentication when signature validation is silently skipped.


Affected software

Apache CloudStack

How to mitigate CVE-2026-68745

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins