CVE-2026-62440
Apache Software Foundation · Apache CloudStack
An improper access control flaw in the Apache CloudStack Kubernetes Service plugin allows unauthenticated users to perform cross-tenant cluster manipulation, including adding or removing nodes.
Executive summary
A critical access control vulnerability in Apache CloudStack allows unauthenticated attackers to manipulate Kubernetes clusters across tenant boundaries, posing a severe risk to infrastructure integrity.
Vulnerability
This is an improper access control vulnerability (CWE-284) located in the Kubernetes Service (CKS) plugin, which can be triggered by an unauthenticated attacker to modify cluster configurations across different tenants.
Business impact
The ability for an unauthenticated actor to manipulate Kubernetes nodes across tenant boundaries represents a total loss of confidentiality and integrity within the cloud management layer. Given the critical CVSS score of 9.1, this vulnerability could lead to unauthorized resource consumption, data exfiltration, or complete service disruption for affected tenants, resulting in significant operational and reputational damage.
Remediation
Immediate Action: Upgrade all instances of Apache CloudStack to version 4.22.1.1 or later immediately to resolve the identified access control flaw.
Proactive Monitoring: Review audit logs for unauthorized API calls targeting the Kubernetes Service (CKS) plugin and monitor for unexpected changes in cluster node topology.
Compensating Controls: Implement strict network segmentation and restrict access to the CloudStack management API to trusted administrative subnets until the patch is deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity and the potential for complete cross-tenant compromise, organizations must prioritize the update to version 4.22.1.1. Rapid deployment of this patch is essential to maintain the isolation and security of the managed Kubernetes environments.
More Apache Software Foundation CVEs
Sources
Originally found and disclosed by George Chen (GitHub: geo-chen), D0HY30N (GitHub: D0HY30N), per the CVE Program record.