CVE-2026-59655
Apache Software Foundation · Apache CloudStack
An exposure of sensitive information exists in the Apache CloudStack OAuth authentication plugin, allowing unauthenticated attackers to view OAuth provider configuration details.
Executive summary
A high-severity information disclosure vulnerability in Apache CloudStack allows unauthenticated remote attackers to access sensitive OAuth configuration data.
Vulnerability
The vulnerability is an exposure of sensitive information (CWE-200) located within the OAuth authentication plugin. It can be triggered by an unauthenticated attacker when listing OAuth providers, potentially exposing credentials or configuration secrets.
Business impact
The successful exploitation of this vulnerability results in the unauthorized disclosure of sensitive security configuration data. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to organizational infrastructure, as exposed OAuth secrets can be leveraged to facilitate further unauthorized access or account takeovers within the cloud management environment.
Remediation
Immediate Action: Upgrade all instances of Apache CloudStack to version 4.20.3.1, 4.22.1.1, or later to incorporate the vendor-supplied fix.
Proactive Monitoring: Review system and access logs for unusual queries directed at the OAuth provider listing endpoints or unexpected API calls originating from unauthorized internal or external IP addresses.
Compensating Controls: Implement strict network-level access controls to limit access to the CloudStack management interface to trusted administrative subnets, effectively reducing the exposure to unauthenticated external actors.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the ability for unauthenticated attackers to extract sensitive configuration data, this vulnerability represents a clear and present risk to the confidentiality of the CloudStack environment. Administrators must prioritize the deployment of the provided security updates to versions 4.20.3.1 or 4.22.1.1 immediately to eliminate this vector for information leakage.
More Apache Software Foundation CVEs
Sources
Originally found and disclosed by Yuliang Xiao <xyl1509410143@outlook.com>, Stijn Simons <stijn.simons@portofantwerpbruges.com>, per the CVE Program record.