CVE-2026-25077
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2026-25077 is an unauthenticated command injection vulnerability in Apache CloudStack affecting the Direct Download Templates feature for KVM hypervisors. Due to missing file name sanitization, authenticated account users can register malicious templates that execute arbitrary code on KVM hosts. Affected versions include Apache CloudStack 4.11.0.0 through 4.20.2.0 and 4.21.0.0 through 4.22.0.0. The vulnerability was disclosed on May 8, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Apache Advisory, OSS-Sec).

Technical details

The root cause is improper control of code generation (CWE-94) stemming from missing sanitization of file names when account users register templates for direct download to primary storage on KVM hypervisors. By default, CloudStack allows account users to register such templates, and the unsanitized file name is passed in a way that enables command injection on the KVM host. The attack vector is network-based, requires only low privileges (a valid CloudStack account), no user interaction, and has low attack complexity, making it straightforward to exploit. The vulnerability was reported by Reza at HazardLab (OSS-Sec, Apache Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code on KVM hypervisor hosts managed by CloudStack, resulting in full compromise of resource integrity and confidentiality, potential data loss, denial of service, and disruption of the entire KVM-based infrastructure. Because KVM hosts underpin virtual machine workloads, compromise can extend to all guest instances running on affected hypervisors, enabling lateral movement across the cloud environment. The impact spans confidentiality, integrity, and availability — all rated High in the CVSS scoring (OSS-Sec, Apache Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Apache CloudStack management interfaces running versions 4.11.0.0–4.20.2.0 or 4.21.0.0–4.22.0.0 with KVM hypervisors configured.
  2. Obtain credentials: Acquire any valid CloudStack account user credentials (low-privilege account sufficient) through phishing, credential stuffing, or other means.
  3. Register malicious template: Using the CloudStack API or UI, register a template for direct download to primary storage targeting KVM hypervisors, embedding a malicious payload in the template file name (e.g., a shell command sequence exploiting the lack of file name sanitization).
  4. Trigger template download: Initiate deployment of an instance using the malicious template, causing the KVM host to process the unsanitized file name and execute the injected command.
  5. Achieve code execution: The injected command executes on the KVM host with the privileges of the CloudStack agent/service, enabling reverse shell establishment, data exfiltration, or further lateral movement across the hypervisor infrastructure (OSS-Sec, Apache Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from KVM hypervisor hosts to external IPs; unusual DNS queries originating from hypervisor nodes; reverse shell traffic (e.g., on non-standard ports) from KVM hosts.
  • Logs: CloudStack management server logs showing template registration requests with anomalous or shell-metacharacter-containing file names; CloudStack agent logs on KVM hosts recording unexpected command execution during template download operations.
  • File System: Unexpected files or scripts written to primary storage directories on KVM hosts; new cron jobs, systemd units, or startup scripts created by the CloudStack agent user; web shells or backdoors placed in accessible directories.
  • Process: Unusual child processes spawned by the CloudStack agent (e.g., /bin/bash, curl, wget, nc, python) on KVM hypervisor hosts; unexpected privilege escalation activity on hypervisor nodes.

Mitigation and workarounds

Upgrade Apache CloudStack to version 4.20.3.0 or 4.22.0.1 (or later), which contain the fix for this vulnerability (Apache Advisory, OSS-Sec). As an interim workaround, restrict template registration capabilities to trusted administrative users only and disable direct download template registration for general account users where possible. Monitor template registration activities for suspicious or anomalous file names containing shell metacharacters. ShapeBlue's security advisory for the 4.20.3.0 and 4.22.0.1 releases provides additional guidance (ShapeBlue).

Community reactions

The vulnerability was disclosed via the Apache security mailing list and the oss-security list on May 8–9, 2026, with credit given to Reza at HazardLab for responsible disclosure (OSS-Sec). ShapeBlue, a major CloudStack contributor, published a security advisory alongside the patched releases (ShapeBlue). The vulnerability received coverage in security aggregators and threat intelligence feeds, and was noted on social platforms including Bluesky and Mastodon by infosec community accounts. Red Hat also tracked the CVE given its relevance to KVM-based infrastructure (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-25199CRITICAL9.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2026-25077HIGH8.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-66467HIGH8.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-66172HIGH8.1
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026
CVE-2025-69233MEDIUM5.3
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesMay 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management