Executive brief
A security flaw in the Apache CloudStack Backup plugin allows any logged-in user to view a list of backups belonging to other accounts. While an attacker cannot view the actual contents of these backups, the exposure of backup metadata could reveal sensitive information about the environment's infrastructure and data retention policies. Organizations using affected versions should upgrade to version 4.22.0.1 to restore proper access controls.
Technical details
An improper authorization logic (CWE-863) exists in the Apache CloudStack Backup plugin versions 4.21.0.0 and 4.22.0.0. An authenticated attacker with access to specific APIs can bypass intended account isolation to enumerate and list backup records across the entire environment. The vulnerability is limited to metadata exposure; the root cause does not permit the attacker to download or view the actual contents of the backups. The issue is resolved in version 4.22.0.1.
Affected products
- Apache CloudStack 4.21.0.0, 4.22.0.0
Timeline
- 2026-05-08: disclosed
- 2026-05-08: advisory
- 2026-05-08: patched: Fixed in version 4.22.0.1