CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6026

As cited

Copy frozen at (site build).

NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

Apache CloudStack released fixes for multiple vulnerabilities across versions 4.12.0.0 through 4.22.1.0, including OS command injection in the NAS backup provider plugin, server-side request forgery (SSRF) in metalink mirror resolution and webhooks, insufficient access control in userdata APIs and authentication plugins, and improper privilege management in two-factor authentication. Additional flaws address user interface encoding issues, command injection in diagnostics APIs, improper access control in Kubernetes Service plugins, and SAML certificate validation bypass. Some vulnerabilities allow authenticated users to execute root or administrative commands on KVM hypervisor hosts, system virtual machines, and virtual routers, or to access sensitive information and tenant data without authorization.

Why it matters: CloudStack administrators and operators must patch immediately to prevent authenticated users from escalating privileges to root, accessing other tenants' data, and bypassing domain and SAML authentication controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

Apache CloudStack released fixes for multiple vulnerabilities across versions 4.12.0.0 through 4.22.1.0, including OS command injection in the NAS backup provider plugin, server-side request forgery (SSRF) in metalink mirror resolution and webhooks, insufficient access control in userdata APIs and authentication plugins, and improper privilege management in two-factor authentication. Additional flaws address user interface encoding issues, command injection in diagnostics APIs, improper access control in Kubernetes Service plugins, and SAML certificate validation bypass. Some vulnerabilities allow authenticated users to execute root or administrative commands on KVM hypervisor hosts, system virtual machines, and virtual routers, or to access sensitive information and tenant data without authorization.

Why it matters: CloudStack administrators and operators must patch immediately to prevent authenticated users from escalating privileges to root, accessing other tenants' data, and bypassing domain and SAML authentication controls.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary