CVE-2026-25077
published 2026-05-08CVE-2026-25077: Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.73%
50.0th percentile
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of the KVM-based infrastructure managed by CloudStack.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | >= 4.11.0.0 < 4.20.3.0 | 4.20.3.0 |
| apache | cloudstack | >= 4.21.0.0 < 4.22.0.1 | 4.22.0.1 |
| apache_software_foundation | apache_cloudstack | 4.11.0 – 4.20.2.0 | — |
| apache_software_foundation | apache_cloudstack | 4.21.0.0 – 4.22.0.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache CloudStack up to 4.20.2.0/4.22.0.0 code injection (EUVD-2026-28549 / WID-SEC-2026-1438)
vuldb·2026-05-10·CVSS 6.3
CVE-2026-25077 [MEDIUM] Apache CloudStack up to 4.20.2.0/4.22.0.0 code injection (EUVD-2026-28549 / WID-SEC-2026-1438)
A vulnerability has been found in Apache CloudStack up to 4.20.2.0/4.22.0.0 and classified as critical. This impacts an unknown function. Performing a manipulation results in code injection.
This vulnerability is known as CVE-2026-25077. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
GHSA-vhgc-6rjx-f6vv: Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hype
ghsa_unreviewed·2026-05-08
CVE-2026-25077 [MEDIUM] CWE-94 GHSA-vhgc-6rjx-f6vv: Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hype
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of the KVM-based infrastructure managed by CloudStack.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-08
Published