cbcvebase.

Apache Cloudstack vulnerabilities

64 known vulnerabilities affecting apache/cloudstack.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH25MEDIUM24LOW3

Vulnerabilities

Page 2 of 4
CVE-2016-6813P3CRITICALCVSS 9.8≥ 4.1.0, ≤ 4.8.1.0v4.9.02018-02-06
CVE-2016-6813 [CRITICAL] CVE-2016-6813: Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to registe Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.
nvd
CVE-2025-66172P3HIGHCVSS 8.1≥ 4.21.0.0, < 4.22.0.12026-05-08
CVE-2025-66172 [HIGH] CWE-359 CVE-2025-66172: The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can restore a volume from any other user's backups and attach the volume to their own VMs. Backup plugin users usi
nvd
CVE-2025-66467P3HIGHCVSS 8.1≥ 4.19.0.0, < 4.20.3.0≥ 4.21.0.0, < 4.22.0.12026-05-08
CVE-2025-66467 [HIGH] CWE-459 CVE-2025-66467: Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated access and secret keys. Users are recommended to upg
nvd
CVE-2025-26521P3HIGHCVSS 8.1≥ 4.17.0.0, < 4.19.3.0≥ 4.20.0.0, < 4.20.1.02025-06-10
CVE-2025-26521 [HIGH] CWE-200 CVE-2025-26521: When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the project who can access the CKS-based Kubernetes cluster, can also access the API key and secret
nvd
CVE-2026-68745P3HIGHCVSS 8.1≥ 4.5.2, < 4.20.3.1v4.22.1.02026-08-21
CVE-2026-68745 [HIGH] CWE-347 CVE-2026-68745: Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on w
nvd
CVE-2026-50222P3HIGHCVSS 7.5≥ 4.18.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-50222 [HIGH] CWE-200 CVE-2026-50222: Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine, exhibit missing or insuffi
nvd
CVE-2024-45693P3HIGHCVSS 8.8≥ 4.15.1.0, < 4.18.2.4≥ 4.19.0.0, < 4.19.1.22024-10-16
CVE-2024-45693 [HIGH] CWE-352 CVE-2024-45693: Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requ Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the requests. This can allow an attacker to gain privileges and access to resources of the authenticated users and may lead to account takeover, disruption, exposure of sensitive data and compromise integr
nvd
CVE-2026-59780P3HIGHCVSS 7.5≥ 4.2.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-59780 [HIGH] CWE-200 CVE-2026-59780: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles. This issue affects Apache CloudSt
nvd
CVE-2026-61397P3HIGHCVSS 7.5≥ 4.19.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-61397 [HIGH] CWE-200 CVE-2026-61397: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue.
nvd
CVE-2026-59655P3HIGHCVSS 7.5≥ 4.19.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-59655 [HIGH] CWE-200 CVE-2026-59655: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the
nvd
CVE-2024-42062P3HIGHCVSS 7.2≥ 4.10.0.0, < 4.18.2.3≥ 4.19.0.0, < 4.19.1.12024-08-07
CVE-2024-42062 [HIGH] CWE-863 CVE-2024-42062: CloudStack account-users by default use username and password based authentication for API and UI ac CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission validation issue that affects Apache CloudStack versions 4.10.0 up to 4.19.1.
nvd
CVE-2022-26779P3HIGHCVSS 7.5fixed in 4.16.1.02022-03-15
CVE-2022-26779 [HIGH] CWE-338 CVE-2022-26779: Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation to Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use
nvd
CVE-2026-66722P3HIGHCVSS 7.2≥ 4.15.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-66722 [HIGH] CWE-285 CVE-2026-66722: Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check only confirms the caller is a Domain Admin, without verifying whether the tar
nvd
CVE-2016-3085P3MEDIUMCVSS 6.5v4.7.0v4.5.1+5 more2016-06-10
CVE-2016-3085 [MEDIUM] CWE-254 CVE-2016-3085: Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.
nvd
CVE-2026-59654P3HIGHCVSS 7.5≥ 4.7.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-59654 [HIGH] CWE-772 CVE-2026-59654: Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped glo Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server. This issue affects Apach
nvd
CVE-2025-66171P3MEDIUMCVSS 6.5≥ 4.21.0.0, < 4.22.0.12026-05-08
CVE-2025-66171 [MEDIUM] CWE-359 CVE-2025-66171: The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any other user of the environment. Backup plugin users using CloudStack 4.21
nvd
CVE-2026-59657P3HIGHCVSS 7.5≥ 4.0.0, < 4.20.3.1≥ 4.21.0.0, < 4.22.1.12026-08-21
CVE-2026-59657 [HIGH] CWE-312 CVE-2026-59657: Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
nvd
CVE-2025-66170P3MEDIUMCVSS 6.5≥ 4.21.0.0, < 4.22.0.12026-05-08
CVE-2025-66170 [MEDIUM] CWE-863 CVE-2025-66170: The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the con
nvd
CVE-2024-29007P3HIGHCVSS 7.3≥ 4.9.1.0, < 4.18.1.1v4.19.0.02024-04-04
CVE-2024-29007 [HIGH] CWE-918 CVE-2024-29007: The CloudStack management server and secondary storage VM could be tricked into making requests to r The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.
nvd
CVE-2013-2756P3MEDIUMCVSS 5.0v4.0.0v4.0.1+1 more2014-05-23
CVE-2013-2756 [MEDIUM] CWE-287 CVE-2013-2756: Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x bef Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.
nvd
Apache Cloudstack vulnerabilities | cvebase