Known Vulnerabilities for Cloudstack by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Cloudstack" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-25199 json | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issu... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2026-25077 json | Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying ins... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2025-69233 json | Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2025-66467 json | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they pre... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2025-66172 json | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-a... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2025-66171 json | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-a... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2025-66170 json | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated... | Not Provided | 2026-05-08 | 2026-05-09 |
| CVE-2022-35741 json | Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerab... | 9.8 - CRITICAL | 2022-07-18 | 2022-07-25 |
| CVE-2022-26779 json | Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite... | 7.5 - HIGH | 2022-03-15 | 2022-03-22 |
| CVE-2019-17562 json | A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions ... | 9.8 - CRITICAL | 2020-05-14 | 2021-07-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Cloudstack | 4.9.3.1 | |||
| Application | Apache | Cloudstack | 4.9.3.0 | |||
| Application | Apache | Cloudstack | 4.9.2.0 | |||
| Application | Apache | Cloudstack | 4.9.1.0 | |||
| Application | Apache | Cloudstack | 4.9.0.1 | |||
| Application | Apache | Cloudstack | 4.9.0 | |||
| Application | Apache | Cloudstack | 4.8.1.1 | |||
| Application | Apache | Cloudstack | 4.8.1.0 | |||
| Application | Apache | Cloudstack | 4.8.1 | |||
| Application | Apache | Cloudstack | 4.8.0.1 | |||
| Application | Apache | Cloudstack | 4.8.0 | |||
| Application | Apache | Cloudstack | 4.8 | |||
| Application | Apache | Cloudstack | 4.7.1.1 | |||
| Application | Apache | Cloudstack | 4.7.1 | |||
| Application | Apache | Cloudstack | 4.7.0 | |||
| Application | Apache | Cloudstack | 4.6.2.1 | |||
| Application | Apache | Cloudstack | 4.6.2 | |||
| Application | Apache | Cloudstack | 4.6.1 | |||
| Application | Apache | Cloudstack | 4.6.0 | |||
| Application | Apache | Cloudstack | 4.5.2.2 |