Executive brief
Apache CloudStack is an open-source cloud orchestration platform used to manage virtual infrastructure and multi-tenant environments. Domain Administrators can query host tags but receive unscoped results showing tags for all hosts in the environment rather than only those assigned to their domain, potentially exposing infrastructure details they should not have access to.
Technical details
The listHostTags API in Apache CloudStack fails to enforce domain-level authorization checks when called by Domain Admins. Although Domain Admins are permitted to call the API by default, the implementation returns all host tags in the system without filtering by the caller's domain scope. This is a broken access control vulnerability allowing Domain Admins to enumerate infrastructure outside their administrative domain. The issue affects versions 4.12.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0, and is fixed in 4.20.3.1 and 4.22.1.1 or later. Authentication as a Domain Admin is required to exploit this issue.
Affected products
- Apache CloudStack 4.12.0.0 through 4.20.3.0, 4.21.0.0 through 4.22.1.0
Timeline
- 2026-08-21: disclosed