CVE-2026-59799
Apache Software Foundation · Apache CloudStack
A privilege management flaw in Apache CloudStack's two-factor authentication plugin allows an authenticated user to bypass the two-factor authentication disable flow.
Executive summary
An improper privilege management vulnerability in Apache CloudStack allows an authenticated user to bypass two-factor authentication security controls.
Vulnerability
This vulnerability (CWE-269) resides in the two-factor authentication plugin of Apache CloudStack. It allows an authenticated user to bypass the controls intended to prevent the disabling of two-factor authentication, effectively weakening the security posture of the affected accounts.
Business impact
The CVSS score of 8.8 highlights the severity of this issue. By bypassing two-factor authentication, an attacker with valid user credentials can compromise accounts that would otherwise be protected, potentially leading to unauthorized data access, administrative control, and significant reputational or operational damage.
Remediation
Immediate Action: Upgrade to Apache CloudStack version 4.20.3.1, 4.22.1.1, or later to address the privilege management flaw.
Proactive Monitoring: Audit user account activity logs for unauthorized changes to authentication settings, specifically focusing on the disabling of two-factor authentication.
Compensating Controls: Enforce strict access control policies and review user roles to ensure that only authorized personnel have the permissions necessary to manage authentication plugins.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Apache CloudStack must prioritize the application of the provided patches. Since this flaw affects the integrity of authentication processes, immediate remediation is necessary to maintain the security and confidentiality of the cloud environment.
More Apache Software Foundation CVEs
Sources
Originally found and disclosed by Erichen <chenyoulong20g@ict.ac.cn>, per the CVE Program record.