CVE-2026-59655

Apache Software Foundation · Apache CloudStack

An exposure of sensitive information exists in the Apache CloudStack OAuth authentication plugin, allowing unauthenticated attackers to view OAuth provider configuration details.

Executive summary

A high-severity information disclosure vulnerability in Apache CloudStack allows unauthenticated remote attackers to access sensitive OAuth configuration data.

Vulnerability

The vulnerability is an exposure of sensitive information (CWE-200) located within the OAuth authentication plugin. It can be triggered by an unauthenticated attacker when listing OAuth providers, potentially exposing credentials or configuration secrets.

Business impact

The successful exploitation of this vulnerability results in the unauthorized disclosure of sensitive security configuration data. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to organizational infrastructure, as exposed OAuth secrets can be leveraged to facilitate further unauthorized access or account takeovers within the cloud management environment.

Remediation

Immediate Action: Upgrade all instances of Apache CloudStack to version 4.20.3.1, 4.22.1.1, or later to incorporate the vendor-supplied fix.

Proactive Monitoring: Review system and access logs for unusual queries directed at the OAuth provider listing endpoints or unexpected API calls originating from unauthorized internal or external IP addresses.

Compensating Controls: Implement strict network-level access controls to limit access to the CloudStack management interface to trusted administrative subnets, effectively reducing the exposure to unauthenticated external actors.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the ability for unauthenticated attackers to extract sensitive configuration data, this vulnerability represents a clear and present risk to the confidentiality of the CloudStack environment. Administrators must prioritize the deployment of the provided security updates to versions 4.20.3.1 or 4.22.1.1 immediately to eliminate this vector for information leakage.

More Apache Software Foundation CVEs

Sources

Originally found and disclosed by Yuliang Xiao <xyl1509410143@outlook.com>, Stijn Simons <stijn.simons@portofantwerpbruges.com>, per the CVE Program record.