SAML Authentication Vulnerability in Apache CloudStack
CVE-2026-68745

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 August 2026

What is CVE-2026-68745?

In specific versions of Apache CloudStack, there exists a vulnerability that exposes the system to certificate validation failures during SAML authentication. An attacker could exploit this issue by forging a SAML response to the management server. The successful attack would require the attacker to either spoof the IP address of the Identity Provider (IdP) or register a malicious URL on the management server. This could lead to unauthorized access as the forged signatures may bypass security checks. It is critical for users to upgrade to versions 4.20.3.1 or 4.22.1.1 and above to mitigate this risk.

Affected Version(s)

Apache CloudStack 4.5.2 <= 4.20.3.0

Apache CloudStack 4.21.0.0 <= 4.22.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses <katriel.moses@gmail.com>
.