Junglewise Threat Intelligence

CVE-2026-59085: Apache CloudStack SSRF in webhook module

CVE-2026-59085 · Severity: critical · CVSS 9.1 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack's webhook delivery system contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to make arbitrary network requests from the CloudStack server itself. This could lead to unauthorized access to internal services, data exfiltration, or lateral movement within the infrastructure. Organizations running affected versions should upgrade immediately to patch the vulnerability.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, triggered during webhook delivery requests. The vulnerability allows an attacker to craft malicious webhook payloads that force the CloudStack server to make requests to arbitrary internal or external hosts, potentially exposing internal services or enabling further attacks. The issue affects versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. No authentication bypass or other preconditions are explicitly required beyond the ability to trigger webhook delivery. Patches are available in versions 4.20.3.1 and 4.22.1.1 or later.

Affected products

  • Apache CloudStack 4.20.0.0 through 4.20.3.0, 4.21.0.0 through 4.22.1.0

Timeline

  • 2026-08-21: disclosed

References

Related threats