
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25077 is an unauthenticated command injection vulnerability in Apache CloudStack affecting the Direct Download Templates feature for KVM hypervisors. Due to missing file name sanitization, authenticated account users can register malicious templates that execute arbitrary code on KVM hosts. Affected versions include Apache CloudStack 4.11.0.0 through 4.20.2.0 and 4.21.0.0 through 4.22.0.0. The vulnerability was disclosed on May 8, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Apache Advisory, OSS-Sec).
The root cause is improper control of code generation (CWE-94) stemming from missing sanitization of file names when account users register templates for direct download to primary storage on KVM hypervisors. By default, CloudStack allows account users to register such templates, and the unsanitized file name is passed in a way that enables command injection on the KVM host. The attack vector is network-based, requires only low privileges (a valid CloudStack account), no user interaction, and has low attack complexity, making it straightforward to exploit. The vulnerability was reported by Reza at HazardLab (OSS-Sec, Apache Advisory).
Successful exploitation allows an attacker to execute arbitrary code on KVM hypervisor hosts managed by CloudStack, resulting in full compromise of resource integrity and confidentiality, potential data loss, denial of service, and disruption of the entire KVM-based infrastructure. Because KVM hosts underpin virtual machine workloads, compromise can extend to all guest instances running on affected hypervisors, enabling lateral movement across the cloud environment. The impact spans confidentiality, integrity, and availability — all rated High in the CVSS scoring (OSS-Sec, Apache Advisory).
/bin/bash, curl, wget, nc, python) on KVM hypervisor hosts; unexpected privilege escalation activity on hypervisor nodes.Upgrade Apache CloudStack to version 4.20.3.0 or 4.22.0.1 (or later), which contain the fix for this vulnerability (Apache Advisory, OSS-Sec). As an interim workaround, restrict template registration capabilities to trusted administrative users only and disable direct download template registration for general account users where possible. Monitor template registration activities for suspicious or anomalous file names containing shell metacharacters. ShapeBlue's security advisory for the 4.20.3.0 and 4.22.0.1 releases provides additional guidance (ShapeBlue).
The vulnerability was disclosed via the Apache security mailing list and the oss-security list on May 8–9, 2026, with credit given to Reza at HazardLab for responsible disclosure (OSS-Sec). ShapeBlue, a major CloudStack contributor, published a security advisory alongside the patched releases (ShapeBlue). The vulnerability received coverage in security aggregators and threat intelligence feeds, and was noted on social platforms including Bluesky and Mastodon by infosec community accounts. Red Hat also tracked the CVE given its relevance to KVM-based infrastructure (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."