Sensitive Information Exposure in Apache CloudStack Webhook Module
CVE-2026-65613

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-65613?

A vulnerability within the Webhook module of Apache CloudStack allows the exposure of sensitive information to unauthorized users while listing and deleting deliveries. This issue affects versions 4.20.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0. To mitigate potential risks, users are advised to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which address the identified vulnerabilities.

Affected Version(s)

Apache CloudStack 4.20.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Bawolski <Lukasz.Bawolski@exea.pl>
.