Improper Authorization Vulnerability in Apache CloudStack for Domain Admins
CVE-2026-66722
Currently unrated
What is CVE-2026-66722?
Apache CloudStack contains a vulnerability that allows a Domain Admin to perform CRUD operations on project roles and permissions across domains. This flaw arises as the system only verifies if the caller is a Domain Admin, neglecting to check if the target project belongs to their domain or subdomain. As a result, a malicious Domain Admin could manipulate project roles and permissions in unrelated domains, which poses a significant security risk.
Affected Version(s)
Apache CloudStack 4.15.0.0 <= 4.20.3.0
Apache CloudStack 4.21.0.0 <= 4.22.1.0