Missing Release of Resource after Effective Lifetime in Apache CloudStack - CVE-2026-59654

 

Missing Release of Resource after Effective Lifetime in Apache CloudStack - CVE-2026-59654

Published: August 24, 2026


Vulnerability identifier: #VU144664
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59654
CWE-ID: CWE-772
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of resource after effective lifetime in scoped global configuration functionality when handling configuration operations across different management server modules and plugins. A remote attacker can trigger resource consumption to cause a denial of service.

The issue affects different modules and plugins of the management server, including Quota and Host-HA.


Affected software

Apache CloudStack

How to mitigate CVE-2026-59654

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.1, 4.22.1.1

External References

Related Security Bulletins