CVE-2025-66172
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2025-66172 is an improper access control vulnerability in the Apache CloudStack Backup plugin affecting versions 4.21.0.0 through 4.22.0.0. The flaw allows any authenticated CloudStack user with access to specific Backup plugin APIs to restore volume backups belonging to other users and attach those volumes to their own virtual machines, crossing tenant boundaries. It was reported by Gabriel Pordeus and publicly disclosed on May 8, 2026 via the Apache security mailing list. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Apache Advisory, OSS-Sec).

Technical details

The root cause is improper access control logic (CWE-359: Exposure of Private Personal Information to an Unauthorized Actor) within the CloudStack Backup plugin, which fails to enforce tenant-level authorization checks when processing volume restore and attach API requests. An authenticated user with low privileges can invoke specific Backup plugin APIs to reference and restore backup volumes owned by other users, then attach those volumes to VMs under their own account. No special configuration beyond having an authenticated account and access to the relevant APIs is required; the Backup plugin must be enabled in the environment. No public proof-of-concept exploit code has been identified at this time (OSS-Sec, Apache Advisory).

Impact

Successful exploitation allows an authenticated attacker to access and read data stored in volume backups belonging to any other user in the CloudStack environment, compromising confidentiality and integrity across tenant boundaries. The attacker can attach the restored volume to their own VM, gaining full read/write access to the victim's data. This is particularly severe in multi-tenant cloud environments where data isolation between customers is a fundamental security requirement. Availability is not directly impacted, but the integrity of tenant data separation is fully undermined (Apache Advisory, OSS-Sec).

Exploitation steps

  1. Reconnaissance: Identify a CloudStack environment running versions 4.21.0.0 through 4.22.0.0 with the Backup plugin enabled. Obtain or compromise a low-privilege authenticated user account.
  2. Enumerate backup resources: Use the CloudStack API (e.g., listBackups or equivalent Backup plugin API calls) to enumerate backup volumes across the environment, including those belonging to other users or tenants.
  3. Initiate unauthorized restore: Call the Backup plugin's restore API (e.g., restoreVolumeFromBackupAndAttachToVM or equivalent) specifying a backup volume ID belonging to another user, bypassing the missing authorization check.
  4. Attach volume to attacker's VM: Specify the attacker's own VM as the target for the restored volume attachment, causing CloudStack to mount the victim's data volume to the attacker-controlled VM.
  5. Access victim data: Log into the attacker's VM and read or exfiltrate data from the newly attached volume, which contains the victim user's files and information (OSS-Sec, Apache Advisory).

Indicators of compromise

  • Logs: CloudStack API audit logs showing calls to Backup plugin restore/attach APIs (e.g., restoreVolumeFromBackupAndAttachToVM) where the requesting user account does not match the owner of the referenced backup volume ID.
  • Logs: Unusual cross-account volume attachment events in CloudStack management server logs (/var/log/cloudstack/management/management-server.log), particularly where a volume from one account is attached to a VM in a different account.
  • Network: API requests to CloudStack management endpoints for backup restore operations originating from unexpected user accounts or at unusual times.
  • File System / VM Activity: Unexpected new disk volumes appearing attached to VMs, especially volumes not provisioned by the VM owner; unusual data access or exfiltration activity from VMs shortly after a new volume attachment event.

Mitigation and workarounds

Apache has released CloudStack version 4.22.0.1, which fixes this vulnerability; all users running 4.21.0.0 through 4.22.0.0 with the Backup plugin enabled should upgrade immediately (Apache Advisory, OSS-Sec). As a temporary workaround if immediate patching is not possible, restrict API access to the Backup plugin for non-administrative users or disable the Backup plugin entirely until the patch can be applied. Administrators should also audit recent backup restoration activities to identify any unauthorized cross-tenant volume access.

Community reactions

ShapeBlue, a major CloudStack contributor, published a security advisory covering the 4.20.3.0 and 4.22.0.1 releases that address this and related issues (ShapeBlue). SecureReading covered the Apache CloudStack vulnerabilities in a broader article (SecureReading). Community reaction has been focused on the multi-tenant data isolation risk, with the vulnerability classified as 'important' severity by the Apache security team.

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-25199CRITICAL9.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2026-25077HIGH8.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-66467HIGH8.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-66172HIGH8.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-69233MEDIUM5.3
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management