Executive brief
Apache CloudStack is an infrastructure-as-code platform used to manage virtual datacenters and cloud environments. A flaw in its SAML authentication mechanism fails to properly validate certificates, allowing an attacker with network access to forge authentication responses and impersonate any user—including administrators—without knowing their credentials. An attacker could gain unauthorized access to critical cloud infrastructure management capabilities.
Technical details
The vulnerability is a certificate validation failure in the SAML authentication implementation. An attacker can forge SAML responses to the management server by spoofing the IP address of the Identity Provider (IdP) or registering a malicious URL in the management server's configuration. The attack requires network positioning (spoofing or URL registration) and results in authentication bypass, allowing unauthorized login with forged signatures. The vulnerability affects CloudStack 4.20.3.0 and 4.22.1.0; patches are available in versions 4.20.3.1, 4.22.1.1, and above.
Affected products
- Apache CloudStack 4.20.3.0, 4.22.1.0
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Fixed in versions 4.20.3.1 and 4.22.1.1 and above