Executive brief
Apache CloudStack's Webhook feature allows administrators to trigger automated actions when certain events occur. A flaw in the module that lists and deletes webhook deliveries exposes sensitive information to unauthorized users who can interact with the affected API endpoints, potentially revealing details about system events and automated workflows.
Technical details
This vulnerability is an information disclosure flaw in Apache CloudStack's Webhook module, specifically in the functionality that lists and deletes webhook delivery records. The vulnerability allows unauthorized actors to access sensitive information through the affected endpoints without proper authorization checks. The issue affects versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Users should upgrade to version 4.20.3.1, 4.22.1.1, or later to remediate the issue.
Affected products
- Apache CloudStack 4.20.0.0 through 4.20.3.0, 4.21.0.0 through 4.22.1.0
Timeline
- 2026-08-21: disclosed