Junglewise Threat Intelligence

CVE-2026-61397: Apache CloudStack sensitive information exposure in OAuth2 authentication

CVE-2026-61397 · Severity: high · CVSS 7.5 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is a cloud management platform used by organizations to provision and manage virtual infrastructure. A vulnerability in its OAuth2 authentication plugin exposes sensitive user information to unauthorized attackers, potentially compromising credentials and user sessions that control access to critical cloud resources.

Technical details

This vulnerability is an information disclosure flaw in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. The vulnerability allows unauthorized actors to access sensitive information during the OAuth2 authentication flow. The issue affects versions 4.19.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Patches are available in versions 4.20.3.1 and 4.22.1.1. The authentication nature of the component suggests the vulnerability is reachable to unauthenticated users during the login process.

Affected products

  • Apache CloudStack 4.19.0.0 through 4.20.3.0, 4.21.0.0 through 4.22.1.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fixes available in CloudStack 4.20.3.1 and 4.22.1.1

References

Related threats