CVE-2025-30675
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2025-30675 is an access control flaw in Apache CloudStack affecting the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this vulnerability by specifying the domainid parameter alongside filter=self or filter=selfexecutable values to gain unauthorized visibility into templates and ISOs belonging to the ROOT domain or unrelated domains. The vulnerability affects Apache CloudStack versions 4.0.0 through 4.19.2.x and 4.20.0.0 through 4.20.0.x, and was publicly disclosed on June 11, 2025. It carries a CVSS v3.1 base score of 4.7 (Medium) (Red Hat CVE, Apache Advisory).

Technical details

The root cause is improper access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the domain resolution logic of the listTemplates and listIsos API handlers. When a Domain Admin or Resource Admin supplies a domainid parameter with filter=self or filter=selfexecutable, the API incorrectly defaults domain resolution to the ROOT domain scope rather than restricting it to the caller's own domain scope. The fix enforces that domain resolution strictly adheres to the caller's scope, preventing cross-domain enumeration. Exploitation requires authenticated access with at minimum Domain Admin or Resource Admin privileges (Apache Advisory, Apache Mailing List).

Impact

A successful exploit allows a malicious admin to enumerate and extract metadata of templates and ISOs belonging to unrelated domains, violating multi-tenant isolation boundaries within Apache CloudStack. This can expose sensitive internal configuration details, template names, and ISO metadata that should be inaccessible to the attacker's domain. While the vulnerability does not allow direct code execution or data modification, the confidentiality breach could facilitate further reconnaissance or targeted attacks against other tenants (Apache Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability requires authenticated access with Domain Admin or Resource Admin privileges, significantly limiting the attack surface. The EPSS score is approximately 0.034% (0.000340), indicating a low probability of exploitation in the near term. CVE-2025-30675 is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat CVE, Apache Advisory).

Exploitation steps

  1. Authenticate as Domain Admin or Resource Admin: Log in to the Apache CloudStack API or UI using credentials for a Domain Admin or Resource Admin account in any non-ROOT domain.
  2. Craft a malicious API request: Call the listTemplates or listIsos API endpoint, supplying the domainid parameter set to the ROOT domain's ID (or another target domain's ID) along with filter=self or filter=selfexecutable.
  3. Bypass access control: Due to the flawed domain resolution logic, the API defaults to the ROOT domain scope instead of restricting results to the caller's domain, returning templates and ISOs outside the attacker's authorized scope.
  4. Enumerate metadata: Review the API response to extract names, IDs, descriptions, and configuration metadata of templates and ISOs belonging to unrelated domains, which can be used for further reconnaissance (Apache Advisory).

Indicators of compromise

  • Logs: Apache CloudStack API audit logs showing listTemplates or listIsos API calls from Domain Admin or Resource Admin accounts that include both a domainid parameter referencing a domain outside the caller's own domain and filter=self or filter=selfexecutable values.
  • Logs: Repeated or automated API calls to listTemplates/listIsos with cross-domain domainid values from a single admin account in a short time window, suggesting enumeration activity.
  • Network: Unusual volume of API responses containing template or ISO metadata from the ROOT domain or unrelated domains returned to a non-ROOT admin session.

Mitigation and workarounds

Apache CloudStack has released patched versions 4.19.3.0 and 4.20.1.0 that fix this vulnerability by ensuring domain resolution strictly adheres to the caller's scope. All users running versions from 4.0.0 through 4.19.2.x or 4.20.0.0 through 4.20.0.x should upgrade immediately. As interim mitigations, organizations should restrict and audit admin-level account permissions, enforce the principle of least privilege for Domain Admin and Resource Admin accounts, and monitor API logs for suspicious cross-domain listTemplates or listIsos calls (Apache Advisory, Apache Mailing List).

Community reactions

Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the disclosure as part of broader reporting on the Apache CloudStack 4.19.3.0 and 4.20.1.0 security releases, which addressed multiple CVEs simultaneously. ShapeBlue, a major CloudStack contributor, published a dedicated security advisory covering the fixes in both releases (ShapeBlue Advisory). Community reaction has been measured given the Medium severity rating and the requirement for privileged access to exploit the flaw.

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59654MEDIUM6.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66797MEDIUM5.4
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-68745NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66722NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66721NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management