Apache CloudStack: Authorization issue with listHostTags for domain admins
Summary
| CVE | CVE-2026-66721 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-21 09:16:40 UTC |
| Updated | 2026-08-21 09:16:40 UTC |
| Description | Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain. This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. |
Risk And Classification
EPSS: 0.001320000 probability, percentile 0.032510000 (date 2026-08-21)
Problem Types: CWE-862 | CWE-862 CWE-862 Missing Authorization
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache CloudStack | affected 4.12.0.0 4.20.3.0 semver | Not specified |
| CNA | Apache Software Foundation | Apache CloudStack | affected 4.21.0.0 4.22.1.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc | [email protected] | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: KQ Wu <[email protected]> (en)
There are currently no legacy QID mappings associated with this CVE.