cbcvebase.
CVE-2026-50222
published 2026-08-21

CVE-2026-50222: Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several…

PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.54%
43.4th percentile
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine, exhibit missing or insufficient access control validation, potentially allowing cross-tenant/cross-account access to userdata resources that belong to other tenants. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The deleteCniConfiguration API, introduced in 4.21.0.0, also exhibits similar behaviour and lacks access validation. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachecloudstack>= 4.18.0.0 < 4.20.3.14.20.3.1
apachecloudstack>= 4.21.0.0 < 4.22.1.14.22.1.1
apache_software_foundationapache_cloudstack4.18.0.0 – 4.20.3.0—
apache_software_foundationapache_cloudstack4.21.0.0 – 4.22.1.0—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.