Improper Access Control in Apache CloudStack's Annotation Functionality
CVE-2026-66797

5.4MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-66797?

The annotation functionality in Apache CloudStack contains an improper access control vulnerability. This flaw allows authenticated users to create comments and view annotations tied to entities they do not own. Specifically, the addAnnotation and listAnnotation APIs fail to properly enforce ownership checks when an entity's UUID is provided. By exploiting this vulnerability, unauthorized users can manipulate annotations, compromising the integrity of comment data across affected services. It is crucial for users to update to versions 4.20.3.1 or 4.22.1.1 or later to mitigate this risk.

Affected Version(s)

Apache CloudStack 4.16.0.0 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Bawolski <lukasz.bawolski@exea.pl>
.