The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup.
Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cloudstack |
|
| Vendors & Products |
Apache
Apache cloudstack |
Fri, 08 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue. | |
| Title | Apache CloudStack: Any user can list backups that they should not have access to | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-09T06:42:58.243Z
Reserved: 2025-11-22T19:26:03.523Z
Link: CVE-2025-66170
Updated: 2026-05-09T06:42:58.243Z
Status : Undergoing Analysis
Published: 2026-05-08T13:16:35.360
Modified: 2026-05-09T07:16:08.070
Link: CVE-2025-66170
No data.