Improper Access Logic in CloudStack Backup Plugin by Apache
CVE-2025-66171

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 May 2026

What is CVE-2025-66171?

The CloudStack Backup Plugin versions 4.21.0.0 and 4.22.0.0 exhibit an improper access control vulnerability, allowing authenticated users to exploit specific APIs. This can lead to the creation of new virtual machines (VMs) utilizing the backups of any user within the CloudStack environment. Users of the Backup Plugin in CloudStack installations are advised to upgrade to version 4.22.0.1 to mitigate this security risk.

Affected Version(s)

Apache CloudStack 4.21.0.0 <= 4.22.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fabricio Duarte <fabricio.duarte.jr@gmail.com>
Gabriel Ortiga Fernandes <gabriel.ortiga@hotmail.com>
Gabriel Pordeus Santos <gabrielpordeus@gmail.com>
.