
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25199 is an authorization bypass vulnerability in the Proxmox extension for Apache CloudStack that allows unauthorized cross-tenant access to virtual machines. The flaw affects Apache CloudStack versions 4.21.0.0 through 4.22.0.0 and was disclosed on May 8, 2026, with a fix released in version 4.22.0.1. The vulnerability was reported by Sander Grendelman and publicly disclosed via the Apache security mailing list and oss-security. It carries a CVSS v3.1 base score of 9.1 (Critical) (Apache Advisory, oss-security).
The root cause is improper authorization and insufficient input validation (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). The Proxmox extension uses a user-editable instance metadata field, proxmox_vmid, to map CloudStack instances to Proxmox virtual machines; however, this field is neither restricted nor validated against tenant ownership. Because Proxmox VM IDs are sequential and predictable integers, a non-privileged attacker can enumerate valid VM IDs belonging to other tenants and modify their own instance's proxmox_vmid setting to point to a target VM. This manipulation causes CloudStack to treat the attacker's API calls as authorized operations against the victim's VM, requiring no authentication beyond a standard tenant account (oss-security, Apache Advisory).
Successful exploitation grants an attacker full lifecycle control over virtual machines belonging to other tenants, including the ability to start, stop, and destroy those VMs. This constitutes a complete multi-tenant isolation breach in cloud environments, exposing sensitive workloads and data of other customers to unauthorized access and destruction. The confidentiality and integrity impacts are both rated HIGH, as an attacker can access VM state and irreversibly destroy infrastructure across tenant boundaries (oss-security, Apache Advisory).
proxmox_vmid value and incrementing/decrementing to identify neighboring tenant VMs.proxmox_vmid instance detail on your own instance to reference the target VM ID belonging to another tenant. This field is user-editable and not validated against tenant ownership.proxmox_vmid now maps to the victim's Proxmox VM, these operations are executed against the target tenant's virtual machine, achieving full unauthorized control (oss-security, Apache Advisory).proxmox_vmid instance details by non-administrative users; repeated modifications to instance details across different VM IDs from the same account.proxmox_vmid values do not match the originally assigned Proxmox VM ID for that tenant's instance — cross-reference CloudStack instance metadata against Proxmox VM ownership records.The primary remediation is to upgrade Apache CloudStack to version 4.22.0.1, which resolves the improper validation of the proxmox_vmid field. For deployments that cannot immediately upgrade, administrators can prevent users from editing the proxmox_vmid instance detail by adding proxmox_vmid to the global configuration parameter user.vm.denied.details in CloudStack. This workaround effectively blocks the attack vector without requiring an upgrade (Apache Advisory, oss-security).
The vulnerability was credited to reporter Sander Grendelman and disclosed through the Apache security mailing list and oss-security on May 8–9, 2026. ShapeBlue, a major CloudStack integrator, published a security advisory covering the 4.20.3.0 and 4.22.0.1 releases (ShapeBlue Advisory). Social media coverage included posts on Mastodon and Bluesky from infosec community accounts, and SystemTek published a blog post summarizing the vulnerability (SystemTek). Community reaction highlighted the severity of the multi-tenant isolation breach in cloud environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."