VendorsApachecloudstackany version
Vulnerabilities

Apache Cloudstack any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2012-4501
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
Published 2012-10-26 · Modified
10.0EPSS 0.078
CVE-2024-50386
Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure
Published 2024-11-12 · Analyzed
9.9EPSS 0.015
CVE-2022-35741
Apache CloudStack SAML Single Sign-On XXE
Published 2022-07-18 · Modified
9.8EPSS 0.081
CVE-2016-6813
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.
Published 2018-02-06 · Modified
9.8EPSS 0.056
CVE-2024-38346
Apache CloudStack: Unauthenticated cluster service port leads to remote execution
Published 2024-07-05 · Modified
9.8EPSS 0.033
CVE-2019-17562
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.
Published 2020-05-14 · Modified
9.8EPSS 0.029
CVE-2015-3252
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
Published 2016-02-08 · Modified
9.8EPSS 0.022
CVE-2024-39864
Apache CloudStack: Integration API service uses dynamic port when disabled
Published 2024-07-05 · Modified
9.8EPSS 0.018
CVE-2024-29006
Apache CloudStack: x-forwarded-for HTTP header parsed by default
Published 2024-04-04 · Modified
9.8EPSS 0.009
CVE-2026-59085
Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module
Published 2026-08-21 · Analyzed
9.1EPSS 0.006
CVE-2026-61398
Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI
Published 2026-08-21 · Analyzed
9.1EPSS 0.006
CVE-2026-62440
Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation
Published 2026-08-21 · Analyzed
9.1EPSS 0.005
CVE-2026-25199
Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access
Published 2026-05-08 · Modified
9.1EPSS 0.005
CVE-2026-61400
Apache CloudStack: Get and Run Diagnostics Command Injection
Published 2026-08-21 · Analyzed
8.8EPSS 0.029
CVE-2026-47359
Apache CloudStack: OS Command Injection due to unsanitized mount command
Published 2026-08-21 · Analyzed
8.8EPSS 0.020
CVE-2026-25077
Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
Published 2026-05-08 · Modified
8.8EPSS 0.007
CVE-2026-50112
Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates
Published 2026-08-21 · Analyzed
8.8EPSS 0.007
CVE-2026-59799
Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow
Published 2026-08-21 · Analyzed
8.8EPSS 0.006
CVE-2025-47713
Apache CloudStack: Domain Admin can reset Admin password in Root Domain
Published 2025-06-10 · Analyzed
8.8EPSS 0.006
CVE-2025-47849
Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain
Published 2025-06-10 · Analyzed
8.8EPSS 0.006
CVE-2024-45693
Apache CloudStack: Request origin validation bypass makes account takeover possible
Published 2024-10-16 · Modified
8.8EPSS 0.005
CVE-2024-45219
Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
Published 2024-10-16 · Analyzed
8.5EPSS 0.012
CVE-2024-41107
Apache CloudStack: SAML Signature Exclusion
Published 2024-07-19 · Modified
8.1EPSS 0.178
CVE-2025-26521
Apache CloudStack: CKS cluster in project exposes user API keys
Published 2025-06-10 · Analyzed
8.1EPSS 0.006
CVE-2025-66172
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
Published 2026-05-08 · Analyzed
8.1EPSS 0.005
CVE-2025-66467
Apache CloudStack: MinIO policy remains intact on bucket deletion
Published 2026-05-08 · Analyzed
8.1EPSS 0.004
CVE-2026-68745
Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP
Published 2026-08-21 · Analyzed
8.1EPSS 0.002
CVE-2022-26779
Apache Cloudstack insecure random number generation affects project email invitation
Published 2022-03-15 · Modified
7.5EPSS 0.029
CVE-2026-59655
Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure
Published 2026-08-21 · Analyzed
7.5EPSS 0.006
CVE-2026-59780
Apache CloudStack: LDAP provider configuration disclosure
Published 2026-08-21 · Analyzed
7.5EPSS 0.006
CVE-2026-61397
Apache CloudStack: OAuth2 Token Cross-Request Leak
Published 2026-08-21 · Analyzed
7.5EPSS 0.006
CVE-2026-59654
Apache CloudStack: DoS caused by database connections leak
Published 2026-08-21 · Analyzed
7.5EPSS 0.006
CVE-2026-50222
Apache CloudStack: Improper access control in Userdata reference APIs
Published 2026-08-21 · Analyzed
7.5EPSS 0.005
CVE-2026-59657
Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
Published 2026-08-21 · Analyzed
7.5EPSS 0.003
CVE-2024-29007
Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences
Published 2024-04-04 · Analyzed
7.3EPSS 0.008
CVE-2024-42062
Apache CloudStack: User Key Exposure to Domain Admins
Published 2024-08-07 · Modified
7.2EPSS 0.009
CVE-2026-66722
Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue
Published 2026-08-21 · Analyzed
7.2EPSS 0.006
CVE-2024-45462
Apache CloudStack: Incomplete session invalidation on web interface logout
Published 2024-10-16 · Modified
7.1EPSS 0.004
CVE-2025-66171
Apache CloudStack: Any user can create a new VM from backups they should not have access to
Published 2026-05-08 · Analyzed
6.5EPSS 0.005
CVE-2025-66170
Apache CloudStack: Any user can list backups that they should not have access to
Published 2026-05-08 · Analyzed
6.5EPSS 0.005
1 / 2Next →