Junglewise Threat Intelligence

CVE-2026-59655: Apache CloudStack OAuth authentication information disclosure

CVE-2026-59655 · Severity: high · CVSS 7.5 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack's OAuth authentication plugin exposes sensitive OAuth provider credentials and configuration details to unauthorized users. When an attacker lists OAuth providers through the vulnerable plugin, they can retrieve configuration information that should remain confidential, potentially compromising authentication systems and allowing further attacks against cloud infrastructure.

Technical details

An information disclosure vulnerability exists in Apache CloudStack's OAuth authentication plugin when listing OAuth providers. The vulnerability allows an unauthenticated or low-privileged attacker to enumerate and retrieve sensitive OAuth provider details including credentials and configuration through the provider listing functionality. The issue affects CloudStack versions 4.19.0.0–4.20.3.0 and 4.21.0.0–4.22.1.0. Patches are available in versions 4.20.3.1 and 4.22.1.1 or later.

Affected products

  • Apache CloudStack 4.19.0.0–4.20.3.0 and 4.21.0.0–4.22.1.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fixes available in versions 4.20.3.1 and 4.22.1.1 or later

References

Related threats