Command Injection Vulnerability in Apache CloudStack Affecting System VMs and Virtual Routers
CVE-2026-61400

8.8HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-61400?

A command injection vulnerability exists within Apache CloudStack’s functionality for running and retrieving diagnostics on system VMs and virtual routers. An attacker with proper permissions can exploit this flaw to execute arbitrary commands with root privileges on affected instances. This can potentially lead to a complete takeover of the system VM or Virtual Router, thereby enabling lateral movement within a CloudStack-managed environment, and may compromise the integrity of guest network traffic managed by the impacted Virtual Router. The affected API endpoints, getDiagnosticsData and runDiagnostics, are limited to Admin role accounts by default, underscoring the importance of maintaining strict access controls. Users are advised to update to version 4.20.3.1 or 4.22.1.1 or later to mitigate this vulnerability.

Affected Version(s)

Apache CloudStack 4.14.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Bawolski <Lukasz.Bawolski@exea.pl>
.