CVE-2026-61400
published 2026-08-21CVE-2026-61400: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality…
PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.91%
86.5th percentile
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers.
An authenticated user holding the permissions required to invoke either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary command execution on the system VM and/or Virtual Router instances, with commands running as root (or as the diagnostics-process user, at minimum). This represents a full compromise of the affected instance and, depending on network segmentation, may provide a foothold for lateral movement within the CloudStack-managed infrastructure, including access to guest network traffic handled by the compromised Virtual Router.
The getDiagnosticsData and runDiagnostics APIs are restricted to only Admin role accounts by default.
This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | >= 4.20.0.0 < 4.20.3.1 | 4.20.3.1 |
| apache | cloudstack | >= 4.21.0.0 < 4.22.1.1 | 4.22.1.1 |
| apache_software_foundation | apache_cloudstack | 4.14.0.0 – 4.20.3.0 | — |
| apache_software_foundation | apache_cloudstack | 4.21.0.0 – 4.22.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache CloudStack up to 4.20.3.0/4.22.1.0 Diagnostics getDiagnosticsData/runDiagnostics command injection (WID-SEC-2026-2962)
vuldb·2026-08-24·CVSS 8.8
CVE-2026-61400 [HIGH] Apache CloudStack up to 4.20.3.0/4.22.1.0 Diagnostics getDiagnosticsData/runDiagnostics command injection (WID-SEC-2026-2962)
A vulnerability classified as very critical has been found in Apache CloudStack up to 4.20.3.0/4.22.1.0. This issue affects the function getDiagnosticsData/runDiagnostics of the component Diagnostics. This manipulation causes command injection.
This vulnerability is tracked as CVE-2026-61400. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers.
ghsa_unreviewed·2026-08-21
CVE-2026-61400 [HIGH] CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers.
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers.
An authenticated user holding the permissions required to invoke either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary command execution on the system VM and/or Virtual Router instances, with commands running as root (or as the diagnostics-process user, at minimum). This represents a full compromise of the affected instance and, depending on network segmentation, may provide a foothold for lateral movement within the CloudStack-managed infrastructure, including access to guest network traffic handled by the compromised Virtual Router.
The getDiagnosticsData and runDiagnostics
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-21
Published