Junglewise Threat Intelligence

CVE-2026-59780: Apache CloudStack information disclosure in LDAP authentication plugin

CVE-2026-59780 · Severity: high · CVSS 7.5 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is an open-source cloud management platform. The LDAP authentication plugin contains a vulnerability where any authenticated user can list sensitive LDAP provider configurations through the listLdapConfigurations API, potentially exposing directory service credentials and connection settings. This could allow attackers to access or compromise directory services used for enterprise authentication.

Technical details

The vulnerability is an information disclosure flaw in Apache CloudStack's LDAP authentication plugin. The listLdapConfigurations API fails to enforce proper access controls, allowing any authenticated user with default roles to retrieve LDAP provider configurations including sensitive settings. No special privileges or additional preconditions are required beyond having a valid user account. An attacker can invoke this API to enumerate and extract LDAP configuration details that should be restricted to administrators, potentially compromising the underlying directory service.

Affected products

  • Apache CloudStack 4.2.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fixed in versions 4.20.3.1, 4.22.1.1 and later

References

Related threats