CVE-2026-68745
Received Received - Intake

SAML Certificate Validation Bypass in Apache CloudStack

Vulnerability report for CVE-2026-68745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Apache Software Foundation

Description

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache cloudstack From 4.20.3.1 (inc)
apache cloudstack From 4.22.1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves certificate validation failures in SAML authentication within Apache CloudStack versions 4.20.3.0 and 4.22.1.0. A malicious actor can forge a SAML response to the management server by spoofing the identity provider's IP address or registering a malicious URL in the server. This allows unauthorized access with forged signatures.

Detection Guidance

This vulnerability involves forged SAML responses in Apache CloudStack due to certificate validation failures. Detection requires checking for unauthorized SAML responses or spoofed IP addresses from identity providers. Review CloudStack management server logs for unexpected SAML authentication attempts or mismatched signatures. Verify registered IdP URLs and ensure only trusted sources are permitted.

Impact Analysis

This vulnerability could allow unauthorized users to gain access to the Apache CloudStack management server by forging SAML responses. This may lead to unauthorized control over cloud resources, data breaches, or other malicious activities depending on the server's configuration and permissions.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access through forged SAML responses. Weak certificate validation may lead to improper authentication, risking data breaches or unauthorized data exposure. Organizations handling sensitive data under these regulations should address this issue promptly.

Mitigation Strategies

Upgrade Apache CloudStack to versions 4.20.3.1 or 4.22.1.1 and above to fix the SAML authentication certificate validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart