Improper Authorization Vulnerability in Apache CloudStack for Domain Admins
CVE-2026-66722

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-66722?

Apache CloudStack contains a vulnerability that allows a Domain Admin to perform CRUD operations on project roles and permissions across domains. This flaw arises as the system only verifies if the caller is a Domain Admin, neglecting to check if the target project belongs to their domain or subdomain. As a result, a malicious Domain Admin could manipulate project roles and permissions in unrelated domains, which poses a significant security risk.

Affected Version(s)

Apache CloudStack 4.15.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KQ Wu <kqmailbox@163.com>
.