CVE-2026-59654
Received Received - Intake

Resource Leak in Apache CloudStack Management Server

Vulnerability report for CVE-2026-59654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Apache Software Foundation

Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server. This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apache cloudstack From 4.7.0 (inc) to 4.20.3.0 (inc)
apache cloudstack From 4.21.0.0 (inc) to 4.22.1.0 (inc)
apache cloudstack 4.20.3.1
apache cloudstack 4.22.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Release of Resource after Effective Lifetime issue in Apache CloudStack's scoped global configuration functionality. It affects multiple modules and plugins of the CloudStack management server, such as Quota and Host-HA. The flaw may cause a denial of service (DoS) scenario for the management server by not releasing resources properly after they are no longer needed.

Detection Guidance

Detection involves checking Apache CloudStack versions and monitoring for resource leaks in affected modules like Quota or Host-HA. No specific commands are provided in the context, but verify version numbers and review logs for unusual resource consumption patterns.

Impact Analysis

The vulnerability can lead to a denial of service (DoS) for the Apache CloudStack management server. This means the server may become unresponsive or crash, disrupting management operations for virtual machines, storage, and networking. Users could experience downtime or degraded performance in their cloud infrastructure.

Compliance Impact

The vulnerability could lead to denial of service (DoS) for the Apache CloudStack management server, potentially disrupting access to critical data or services. This may impact compliance with GDPR or HIPAA by compromising availability requirements, as both regulations mandate timely access to personal or health data.

Mitigation Strategies

Upgrade Apache CloudStack to version 4.20.3.1 or 4.22.1.1 or later to fix the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart