CVE-2026-66721
Received Received - Intake

Missing Authorization in CloudStack Host Tags Listing

Vulnerability report for CVE-2026-66721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Apache Software Foundation

Description

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain. This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apache cloudstack From 4.12.0.0 (inc) to 4.20.3.0 (inc)
apache cloudstack From 4.21.0.0 (inc) to 4.22.1.0 (inc)
apache cloudstack 4.20.3.1
apache cloudstack 4.22.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in Apache CloudStack's host tags listing functionality. Domain Admins can call the listHostTags API but receive host tags for all hosts in the environment instead of only their domain's hosts.

Detection Guidance

To detect this vulnerability, check if Domain Admins can list host tags for all hosts in the environment. Verify API responses from listHostTags include hosts outside their domain. Compare results against expected domain-scoped access.

Impact Analysis

An attacker with Domain Admin privileges could access host tags for hosts outside their domain, potentially exposing sensitive infrastructure information or enabling further attacks.

Compliance Impact

This could violate data access and segregation requirements in GDPR and HIPAA by allowing unauthorized access to host information across domains.

Mitigation Strategies

Upgrade Apache CloudStack to version 4.20.3.1, 4.22.1.1, or later to fix the missing authorization issue in host tags listing for domain admins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart