Executive brief
Apache CloudStack is an open-source platform used to build and manage large networks of virtual machines. A security flaw in its Backup plugin allows any logged-in user to access and use backups belonging to other users. This could lead to unauthorized data access or the creation of new virtual machines containing sensitive information from other accounts.
Technical details
An improper access control vulnerability (CWE-359) exists in the Apache CloudStack Backup plugin versions 4.21.0.0 and 4.22.0.0. The root cause is flawed access logic within the plugin's API handling. An authenticated attacker with standard user-level access can leverage specific APIs to reference and restore backups that do not belong to their account. This allows the attacker to instantiate new virtual machines based on the disk images of other users, leading to unauthorized disclosure of private data. The issue is resolved in CloudStack version 4.22.0.1.
Affected products
- Apache CloudStack 4.21.0.0 through 4.22.0.0
Timeline
- 2026-05-08: disclosed
- 2026-05-08: advisory
- 2026-05-08: patched: Fixed in version 4.22.0.1