Command Injection Vulnerability in Apache CloudStack Affecting System VMs and Virtual Routers
CVE-2026-61400

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-61400?

A command injection vulnerability exists within Apache CloudStack’s functionality for running and retrieving diagnostics on system VMs and virtual routers. An attacker with proper permissions can exploit this flaw to execute arbitrary commands with root privileges on affected instances. This can potentially lead to a complete takeover of the system VM or Virtual Router, thereby enabling lateral movement within a CloudStack-managed environment, and may compromise the integrity of guest network traffic managed by the impacted Virtual Router. The affected API endpoints, getDiagnosticsData and runDiagnostics, are limited to Admin role accounts by default, underscoring the importance of maintaining strict access controls. Users are advised to update to version 4.20.3.1 or 4.22.1.1 or later to mitigate this vulnerability.

Affected Version(s)

Apache CloudStack 4.14.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Bawolski <Lukasz.Bawolski@exea.pl>
.