Vulnerability in Apache CloudStack Affects Kubernetes Clusters Created by Users
CVE-2025-26521
What is CVE-2025-26521?
An issue in Apache CloudStack allows project members to access the 'kubeadmin' user's API key and secret key when a CKS-based Kubernetes cluster is created. This exposure enables unauthorized users to impersonate the creator and perform actions that can compromise the resources and integrity of the creator's account. To mitigate this risk, users should update to versions 4.19.3.0 or 4.20.1.0 and implement proper service accounts for project-specific clusters. Following security best practices is essential to safeguarding sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache CloudStack 4.17.0.0 < 4.19.3.0
Apache CloudStack 4.20.0.0 < 4.20.1.0
References
CVSS V3.1
Timeline
Vulnerability published