Apache / Cloudstack
65 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59654 | Apache CloudStack: DoS caused by database connections leak | MEDIUM | 6.8 | Aug 21, 2026 |
| CVE-2026-47359 | Apache CloudStack: OS Command Injection due to unsanitized mount command | HIGH | 8.8 | Aug 21, 2026 |
| CVE-2026-50112 | Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates | HIGH | 8.8 | Aug 21, 2026 |
| CVE-2026-50222 | Apache CloudStack: Improper access control in Userdata reference APIs | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-59085 | Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module | CRITICAL | 9.1 | Aug 21, 2026 |
| CVE-2026-59655 | Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-59657 | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-59780 | Apache CloudStack: LDAP provider configuration disclosure | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-59799 | Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow | HIGH | 8.8 | Aug 21, 2026 |
| CVE-2026-61397 | Apache CloudStack: OAuth2 Token Cross-Request Leak | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-61398 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI | CRITICAL | 9.1 | Aug 21, 2026 |
| CVE-2026-61399 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI | MEDIUM | 4.8 | Aug 21, 2026 |
| CVE-2026-61400 | Apache CloudStack: Get and Run Diagnostics Command Injection | HIGH | 8.8 | Aug 21, 2026 |
| CVE-2026-61422 | Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate | MEDIUM | 4.3 | Aug 21, 2026 |
| CVE-2026-62440 | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation | CRITICAL | 9.1 | Aug 21, 2026 |
| CVE-2026-65613 | Apache CloudStack: Webhook Deliveries Incorrect Access | MEDIUM | 4.3 | Aug 21, 2026 |
| CVE-2026-66721 | Apache CloudStack: Authorization issue with listHostTags for domain admins | LOW | 2.7 | Aug 21, 2026 |
| CVE-2026-66722 | Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue | HIGH | 7.2 | Aug 21, 2026 |
| CVE-2026-66797 | Apache CloudStack: Unauthorised comment creation and disclosure | HIGH | 8.5 | Aug 21, 2026 |
| CVE-2026-68745 | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP | HIGH | 8.1 | Aug 21, 2026 |
| CVE-2026-25199 | Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access | CRITICAL | 9.1 | May 8, 2026 |
| CVE-2026-25077 | Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates | HIGH | 8.8 | May 8, 2026 |
| CVE-2025-69233 | Apache CloudStack: Domain/account resources limits not honored | MEDIUM | 6.5 | May 8, 2026 |
| CVE-2025-66467 | Apache CloudStack: MinIO policy remains intact on bucket deletion | HIGH | 8.1 | May 8, 2026 |
| CVE-2025-66172 | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to | HIGH | 8.1 | May 8, 2026 |
Showing 1 to 25 of 65 CVEs