Improper Access Control in Apache CloudStack's Annotation Functionality
CVE-2026-66797

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-66797?

The annotation functionality in Apache CloudStack contains an improper access control vulnerability. This flaw allows authenticated users to create comments and view annotations tied to entities they do not own. Specifically, the addAnnotation and listAnnotation APIs fail to properly enforce ownership checks when an entity's UUID is provided. By exploiting this vulnerability, unauthorized users can manipulate annotations, compromising the integrity of comment data across affected services. It is crucial for users to update to versions 4.20.3.1 or 4.22.1.1 or later to mitigate this risk.

Affected Version(s)

Apache CloudStack 4.16.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Bawolski <lukasz.bawolski@exea.pl>
.