Missing Release of Resource after Effective Lifetime in Apache CloudStack - CVE-2026-59654
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resource after effective lifetime in scoped global configuration functionality when handling configuration operations across different management server modules and plugins. A remote attacker can trigger resource consumption to cause a denial of service.
The issue affects different modules and plugins of the management server, including Quota and Host-HA.