CVE-2026-59654
- EPSS 0.23%
- Veröffentlicht 21.08.2026 13:18:17
- Zuletzt bearbeitet 27.08.2026 01:41:35
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may...
CVE-2026-47359
- EPSS -
- Veröffentlicht 21.08.2026 08:30:07
- Zuletzt bearbeitet 27.08.2026 00:06:21
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introdu...
CVE-2026-50112
- EPSS -
- Veröffentlicht 21.08.2026 08:29:41
- Zuletzt bearbeitet 27.08.2026 00:07:43
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file,...
CVE-2026-50222
- EPSS -
- Veröffentlicht 21.08.2026 08:29:17
- Zuletzt bearbeitet 27.08.2026 00:37:58
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, res...
CVE-2026-59085
- EPSS -
- Veröffentlicht 21.08.2026 08:28:51
- Zuletzt bearbeitet 27.08.2026 00:38:57
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are re...
CVE-2026-59655
- EPSS -
- Veröffentlicht 21.08.2026 08:28:14
- Zuletzt bearbeitet 27.08.2026 00:34:11
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through...
CVE-2026-59657
- EPSS -
- Veröffentlicht 21.08.2026 08:27:53
- Zuletzt bearbeitet 27.08.2026 00:30:51
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgr...
CVE-2026-59780
- EPSS -
- Veröffentlicht 21.08.2026 08:27:16
- Zuletzt bearbeitet 27.08.2026 00:29:15
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLda...
CVE-2026-59799
- EPSS -
- Veröffentlicht 21.08.2026 08:26:52
- Zuletzt bearbeitet 27.08.2026 00:24:58
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0...
CVE-2026-61397
- EPSS -
- Veröffentlicht 21.08.2026 08:26:25
- Zuletzt bearbeitet 27.08.2026 00:21:49
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through...