CVE-2026-62440

Apache Software Foundation · Apache CloudStack

An improper access control flaw in the Apache CloudStack Kubernetes Service plugin allows unauthenticated users to perform cross-tenant cluster manipulation, including adding or removing nodes.

Executive summary

A critical access control vulnerability in Apache CloudStack allows unauthenticated attackers to manipulate Kubernetes clusters across tenant boundaries, posing a severe risk to infrastructure integrity.

Vulnerability

This is an improper access control vulnerability (CWE-284) located in the Kubernetes Service (CKS) plugin, which can be triggered by an unauthenticated attacker to modify cluster configurations across different tenants.

Business impact

The ability for an unauthenticated actor to manipulate Kubernetes nodes across tenant boundaries represents a total loss of confidentiality and integrity within the cloud management layer. Given the critical CVSS score of 9.1, this vulnerability could lead to unauthorized resource consumption, data exfiltration, or complete service disruption for affected tenants, resulting in significant operational and reputational damage.

Remediation

Immediate Action: Upgrade all instances of Apache CloudStack to version 4.22.1.1 or later immediately to resolve the identified access control flaw.

Proactive Monitoring: Review audit logs for unauthorized API calls targeting the Kubernetes Service (CKS) plugin and monitor for unexpected changes in cluster node topology.

Compensating Controls: Implement strict network segmentation and restrict access to the CloudStack management API to trusted administrative subnets until the patch is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity and the potential for complete cross-tenant compromise, organizations must prioritize the update to version 4.22.1.1. Rapid deployment of this patch is essential to maintain the isolation and security of the managed Kubernetes environments.

More Apache Software Foundation CVEs

Sources

Originally found and disclosed by George Chen (GitHub: geo-chen), D0HY30N (GitHub: D0HY30N), per the CVE Program record.