Command Injection Vulnerability in Apache CloudStack Affecting System VMs and Virtual Routers
CVE-2026-61400
What is CVE-2026-61400?
A command injection vulnerability exists within Apache CloudStackâs functionality for running and retrieving diagnostics on system VMs and virtual routers. An attacker with proper permissions can exploit this flaw to execute arbitrary commands with root privileges on affected instances. This can potentially lead to a complete takeover of the system VM or Virtual Router, thereby enabling lateral movement within a CloudStack-managed environment, and may compromise the integrity of guest network traffic managed by the impacted Virtual Router. The affected API endpoints, getDiagnosticsData and runDiagnostics, are limited to Admin role accounts by default, underscoring the importance of maintaining strict access controls. Users are advised to update to version 4.20.3.1 or 4.22.1.1 or later to mitigate this vulnerability.
Affected Version(s)
Apache CloudStack 4.14.0.0 <= 4.20.3.0
Apache CloudStack 4.21.0.0 <= 4.22.1.0