SAML Authentication Vulnerability in Apache CloudStack
CVE-2026-68745
Currently unrated
What is CVE-2026-68745?
In specific versions of Apache CloudStack, there exists a vulnerability that exposes the system to certificate validation failures during SAML authentication. An attacker could exploit this issue by forging a SAML response to the management server. The successful attack would require the attacker to either spoof the IP address of the Identity Provider (IdP) or register a malicious URL on the management server. This could lead to unauthorized access as the forged signatures may bypass security checks. It is critical for users to upgrade to versions 4.20.3.1 or 4.22.1.1 and above to mitigate this risk.
Affected Version(s)
Apache CloudStack 4.5.2 <= 4.20.3.0
Apache CloudStack 4.21.0.0 <= 4.22.1.0