Apache cloudstack是美国Apache基金会开源的一套云计算管理平台。 Apache CloudStack 4.20.0.0版本至4.20.3.0版本和4.21.0.0版本至4.22.1.0版本存在命令注入漏洞,该漏洞源于命令注入,由于对命令中特殊元素中和不当,经过身份验证的用户通过getDiagnosticsData和runDiagnostics功能可以执行任意命令,可能导致受影响的实例被完全破坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.14.0.0≤ 4.20.3.0 |
affected |
4.21.0.0≤ 4.22.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.14.0.0 ~ 4.20.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59654 | 6.8 MEDIUM | Apache CloudStack: DoS caused by database connections leak |
| CVE-2026-59799 | Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow | |
| CVE-2026-63046 | Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials | |
| CVE-2026-47359 | Apache CloudStack: OS Command Injection due to unsanitized mount command | |
| CVE-2026-50112 | Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates | |
| CVE-2026-50222 | Apache CloudStack: Improper access control in Userdata reference APIs | |
| CVE-2026-59085 | Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module | |
| CVE-2026-59655 | Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure | |
| CVE-2026-59657 | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob | |
| CVE-2026-59780 | Apache CloudStack: LDAP provider configuration disclosure | |
| CVE-2026-68745 | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP | |
| CVE-2026-61397 | Apache CloudStack: OAuth2 Token Cross-Request Leak | |
| CVE-2026-61398 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Fun | |
| CVE-2026-61399 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI | |
| CVE-2026-61422 | Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate | |
| CVE-2026-62440 | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulatio | |
| CVE-2026-65613 | Apache CloudStack: Webhook Deliveries Incorrect Access | |
| CVE-2026-66721 | Apache CloudStack: Authorization issue with listHostTags for domain admins | |
| CVE-2026-66722 | Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue | |
| CVE-2026-66797 | Apache CloudStack: Unauthorised comment creation and disclosure |
No comments yet