CloudStack 中域管理员对项目角色及项目角色权限的增删改查操作存在权限验证不当漏洞。 域管理员不仅可以对自己所属域中的项目创建、更新、删除和列出项目角色及项目角色权限,还可以对其他域(包括无关域)中的项目进行相同操作。系统仅校验调用者是否为域管理员,而未验证目标项目是否属于该域管理员所属的域或其子域。这使得恶意域管理员能够篡改其他无关域中的项目角色和权限设置。 此问题影响 Apache CloudStack 以下版本:4.15.0.0 至 4.20.3.0,以及 4.21.0.0 至 4.22.1.0。 建
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.15.0.0≤ 4.20.3.0 |
affected |
4.21.0.0≤ 4.22.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.15.0.0 ~ 4.20.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59654 | 6.8 MEDIUM | Apache CloudStack: DoS caused by database connections leak |
| CVE-2026-61397 | Apache CloudStack: OAuth2 Token Cross-Request Leak | |
| CVE-2026-68745 | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP | |
| CVE-2026-66797 | Apache CloudStack: Unauthorised comment creation and disclosure | |
| CVE-2026-66721 | Apache CloudStack: Authorization issue with listHostTags for domain admins | |
| CVE-2026-65613 | Apache CloudStack: Webhook Deliveries Incorrect Access | |
| CVE-2026-62440 | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulatio | |
| CVE-2026-61422 | Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate | |
| CVE-2026-61400 | Apache CloudStack: Get and Run Diagnostics Command Injection | |
| CVE-2026-61399 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI | |
| CVE-2026-61398 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Fun | |
| CVE-2026-59799 | Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow | |
| CVE-2026-59780 | Apache CloudStack: LDAP provider configuration disclosure | |
| CVE-2026-59657 | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob | |
| CVE-2026-59655 | Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure | |
| CVE-2026-59085 | Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module | |
| CVE-2026-50222 | Apache CloudStack: Improper access control in Userdata reference APIs | |
| CVE-2026-50112 | Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates | |
| CVE-2026-47359 | Apache CloudStack: OS Command Injection due to unsanitized mount command | |
| CVE-2026-63046 | Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials |
No comments yet