Executive brief
Apache CloudStack's two-factor authentication plugin contains a flaw that allows attackers to bypass the two-factor authentication disable workflow through improper privilege validation. This vulnerability could enable unauthorized users to disable two-factor authentication protections on accounts, potentially leading to account takeover and unauthorized access to cloud infrastructure management functions.
Technical details
The vulnerability is a privilege management flaw in Apache CloudStack's two-factor authentication plugin that permits bypassing the disable flow for two-factor authentication. The issue stems from improper validation of user privileges when processing two-factor authentication disable requests, allowing an attacker to circumvent authentication controls. No specific preconditions regarding authentication are explicitly documented, though the attack surface likely involves the CloudStack management API or web interface. Successful exploitation allows an attacker to disable two-factor authentication protections, potentially leading to account compromise. Patches are available in versions 4.20.3.1, 4.22.1.1, and later.
Affected products
- Apache CloudStack 4.18.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0
Timeline
- 2026-08-21: disclosed