Junglewise Threat Intelligence

CVE-2026-61399: Apache CloudStack improper output encoding in Lock User UI

CVE-2026-61399 · Severity: medium · CVSS 4.8 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is a cloud infrastructure management platform used by organizations to manage virtual machines and cloud resources. A vulnerability in the user locking feature of the web interface allows improper encoding of output, which could enable attackers to inject malicious code that affects other users interacting with that feature.

Technical details

An Improper Encoding or Escaping of Output vulnerability (CWE-116) exists in Apache CloudStack's UI when using the Lock User functionality. The vulnerability stems from insufficient output encoding/escaping in the web interface, potentially allowing stored or reflected XSS attacks. The attack vector is network-accessible via the CloudStack UI. Exploitation requires network access to the CloudStack management interface; depending on the context, user interaction or prior authentication may be required. An attacker can inject malicious scripts that execute in the context of authenticated users' browsers. Patches are available in versions 4.20.3.1, 4.22.1.1, and later.

Affected products

  • Apache CloudStack 4.20.0.0 to 4.20.3.0, 4.21.0.0 to 4.22.1.0

Timeline

  • 2026-08-21: disclosed

References

Related threats