CVE-2025-66467
published 2026-05-08CVE-2025-66467: Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user…
PriorityP353high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.37%
29.5th percentile
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated access and secret keys.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | >= 4.19.0.0 < 4.20.3.0 | 4.20.3.0 |
| apache | cloudstack | >= 4.21.0.0 < 4.22.0.1 | 4.22.0.1 |
| apache_software_foundation | apache_cloudstack | 4.19.0.0 – 4.20.2.0 | — |
| apache_software_foundation | apache_cloudstack | 4.21.0.0 – 4.22.0.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-08
Published