CVE-2026-61397

Apache Software Foundation · Apache CloudStack

An exposure of sensitive information vulnerability exists in the Apache CloudStack OAuth2 and Google OAuth integration, allowing unauthenticated remote access to sensitive data.

Executive summary

A high-severity information exposure vulnerability in Apache CloudStack allows unauthenticated attackers to access sensitive data, necessitating an immediate update to patched versions.

Vulnerability

The flaw is an exposure of sensitive information (CWE-200) located within the OAuth2 authentication plugin and Google OAuth integration. It allows an unauthenticated remote attacker to gain unauthorized access to sensitive information without requiring prior system privileges.

Business impact

Successful exploitation allows unauthorized actors to access sensitive configuration or user data, which could lead to further compromise of the cloud management environment. Given the CVSS 3.1 score of 7.5, this vulnerability represents a significant risk to the confidentiality of infrastructure management data, potentially leading to unauthorized system access or lateral movement within the cloud environment.

Remediation

Immediate Action: Upgrade Apache CloudStack installations to version 4.20.3.1 or 4.22.1.1 immediately to resolve the vulnerability.

Proactive Monitoring: Review authentication logs for suspicious access patterns or unauthorized OAuth token requests originating from unknown IP addresses.

Compensating Controls: Implement strict network access control lists to restrict access to the CloudStack management interface to trusted administrative subnets only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Apache CloudStack must prioritize this update as part of their next maintenance cycle to prevent unauthorized data exposure. Because this vulnerability is remotely exploitable without authentication, the risk of data compromise is high. Administrators should verify their current version strings against the affected ranges and apply the provided patches as soon as possible.

More Apache Software Foundation CVEs

Sources

Originally found and disclosed by Katriel Moses <katriel.moses@gmail.com>, "Network and Cloud Laboratory (NaCl) KMITL" <nacl@kmitl.ac.th>, with Paratpanu Pechsaman <66010542@kmitl.ac.th> (analyst), Nutthawat Charoensiriphong <68010321@kmitl.ac.th> (analyst), Panabordee Panitchakit <68010697@kmitl.ac.th> (analyst), per the CVE Program record.