Apache CloudStack 的 NAS 备份提供商插件中存在“OS 命令注入”漏洞,即对 OS 命令中使用的特殊元素处理不当(Improper Neutralization of Special Elements used in an OS Command)。 API(自版本 4.20.0.0 起可用)和 API(在版本 4.22.0.0 中引入)接受未经验证和清理的备份仓库命令参数。恶意操作员账户可利用此漏洞注入任意命令,当任何后续账户执行备份恢复操作时,这些命令将在 KVM 虚拟机监控程序主机上执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.20.0.0≤ 4.20.3.0 |
affected |
4.21.0.0≤ 4.22.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.20.0.0 ~ 4.20.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59654 | 6.8 MEDIUM | Apache CloudStack: DoS caused by database connections leak |
| CVE-2026-61398 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Fun | |
| CVE-2026-68745 | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP | |
| CVE-2026-66797 | Apache CloudStack: Unauthorised comment creation and disclosure | |
| CVE-2026-66722 | Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue | |
| CVE-2026-66721 | Apache CloudStack: Authorization issue with listHostTags for domain admins | |
| CVE-2026-65613 | Apache CloudStack: Webhook Deliveries Incorrect Access | |
| CVE-2026-62440 | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulatio | |
| CVE-2026-61422 | Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate | |
| CVE-2026-61400 | Apache CloudStack: Get and Run Diagnostics Command Injection | |
| CVE-2026-61399 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI | |
| CVE-2026-61397 | Apache CloudStack: OAuth2 Token Cross-Request Leak | |
| CVE-2026-59799 | Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow | |
| CVE-2026-59780 | Apache CloudStack: LDAP provider configuration disclosure | |
| CVE-2026-59657 | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob | |
| CVE-2026-59655 | Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure | |
| CVE-2026-59085 | Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module | |
| CVE-2026-50222 | Apache CloudStack: Improper access control in Userdata reference APIs | |
| CVE-2026-50112 | Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates | |
| CVE-2026-63046 | Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials |
No comments yet