Junglewise Threat Intelligence

CVE-2025-66172: The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access i

CVE-2025-66172 · Severity: high · CVSS 8.1 · Published 2026-05-08

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is an open-source platform used to manage and deploy large networks of virtual machines. A security flaw in its Backup plugin allows any logged-in user to access and restore data from other users' backups. This means an attacker could steal sensitive information by attaching another customer's backup volumes to their own virtual machines.

Technical details

An improper access control vulnerability (CWE-359) exists in the Apache CloudStack Backup plugin versions 4.21.0.0 and 4.22.0.0. The root cause is flawed access logic within the plugin's API handlers. An authenticated attacker with standard user-level access can invoke specific APIs to restore a volume from a backup belonging to a different user or account. Once restored, the attacker can attach this volume to a virtual machine under their control, leading to unauthorized data disclosure and integrity compromise. The issue is resolved in CloudStack version 4.22.0.1.

Affected products

  • Apache CloudStack 4.21.0.0 through 4.22.0.0

Timeline

  • 2026-05-08: disclosed: Initial disclosure by Apache Software Foundation
  • 2026-05-08: advisory: NVD publication date
  • 2026-05-08: patched: Fix released in version 4.22.0.1

References