
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66172 is an improper access control vulnerability in the Apache CloudStack Backup plugin affecting versions 4.21.0.0 through 4.22.0.0. The flaw allows any authenticated CloudStack user with access to specific Backup plugin APIs to restore volume backups belonging to other users and attach those volumes to their own virtual machines, crossing tenant boundaries. It was reported by Gabriel Pordeus and publicly disclosed on May 8, 2026 via the Apache security mailing list. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Apache Advisory, OSS-Sec).
The root cause is improper access control logic (CWE-359: Exposure of Private Personal Information to an Unauthorized Actor) within the CloudStack Backup plugin, which fails to enforce tenant-level authorization checks when processing volume restore and attach API requests. An authenticated user with low privileges can invoke specific Backup plugin APIs to reference and restore backup volumes owned by other users, then attach those volumes to VMs under their own account. No special configuration beyond having an authenticated account and access to the relevant APIs is required; the Backup plugin must be enabled in the environment. No public proof-of-concept exploit code has been identified at this time (OSS-Sec, Apache Advisory).
Successful exploitation allows an authenticated attacker to access and read data stored in volume backups belonging to any other user in the CloudStack environment, compromising confidentiality and integrity across tenant boundaries. The attacker can attach the restored volume to their own VM, gaining full read/write access to the victim's data. This is particularly severe in multi-tenant cloud environments where data isolation between customers is a fundamental security requirement. Availability is not directly impacted, but the integrity of tenant data separation is fully undermined (Apache Advisory, OSS-Sec).
listBackups or equivalent Backup plugin API calls) to enumerate backup volumes across the environment, including those belonging to other users or tenants.restoreVolumeFromBackupAndAttachToVM or equivalent) specifying a backup volume ID belonging to another user, bypassing the missing authorization check.restoreVolumeFromBackupAndAttachToVM) where the requesting user account does not match the owner of the referenced backup volume ID./var/log/cloudstack/management/management-server.log), particularly where a volume from one account is attached to a VM in a different account.Apache has released CloudStack version 4.22.0.1, which fixes this vulnerability; all users running 4.21.0.0 through 4.22.0.0 with the Backup plugin enabled should upgrade immediately (Apache Advisory, OSS-Sec). As a temporary workaround if immediate patching is not possible, restrict API access to the Backup plugin for non-administrative users or disable the Backup plugin entirely until the patch can be applied. Administrators should also audit recent backup restoration activities to identify any unauthorized cross-tenant volume access.
ShapeBlue, a major CloudStack contributor, published a security advisory covering the 4.20.3.0 and 4.22.0.1 releases that address this and related issues (ShapeBlue). SecureReading covered the Apache CloudStack vulnerabilities in a broader article (SecureReading). Community reaction has been focused on the multi-tenant data isolation risk, with the vulnerability classified as 'important' severity by the Apache security team.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."