Improper Authorization Vulnerability in Apache CloudStack for Domain Admins
CVE-2026-66722

7.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-66722?

Apache CloudStack contains a vulnerability that allows a Domain Admin to perform CRUD operations on project roles and permissions across domains. This flaw arises as the system only verifies if the caller is a Domain Admin, neglecting to check if the target project belongs to their domain or subdomain. As a result, a malicious Domain Admin could manipulate project roles and permissions in unrelated domains, which poses a significant security risk.

Affected Version(s)

Apache CloudStack 4.15.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KQ Wu <kqmailbox@163.com>
.