Junglewise Threat Intelligence

CVE-2026-62440: Apache CloudStack improper access control in Kubernetes Service plugin

CVE-2026-62440 · Severity: critical · CVSS 9.1 · Published 2026-08-21

Technologies: Apache Cloudstack. Vendors: Apache.

Executive brief

Apache CloudStack is a cloud management platform that orchestrates infrastructure and virtual machines. The Kubernetes Service (CKS) plugin allows administrators to deploy and manage Kubernetes clusters within CloudStack. An improper access control vulnerability allows attackers to manipulate Kubernetes clusters across different customer tenants—adding or removing worker nodes—without proper authorization, compromising multi-tenant isolation and cluster integrity.

Technical details

This is an improper access control vulnerability (CWE-284) in the Kubernetes Service plugin of Apache CloudStack that fails to properly enforce tenant isolation when modifying cluster node membership. The vulnerability is exploitable when adding or removing nodes to/from a Kubernetes cluster, allowing an authenticated or cross-tenant attacker to manipulate clusters belonging to other tenants. The root cause lies in insufficient authorization checks in the node management API endpoints within the CKS plugin. Affected versions range from 4.21.0.0 through 4.22.1.0; the fix is available in version 4.22.1.1 and later. No active exploitation in the wild has been reported at this time.

Affected products

  • Apache CloudStack 4.21.0.0 through 4.22.1.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fix available in version 4.22.1.1 and later

References

Related threats