
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66721 is a missing authorization vulnerability in Apache CloudStack's listHostTags API that allows Domain Admins to retrieve host tags for all hosts across the entire environment, rather than being restricted to hosts dedicated to their own domain. It affects Apache CloudStack versions 4.12.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The vulnerability was disclosed on August 21, 2026, with patches available in versions 4.20.3.1 and 4.22.1.1. It is classified as HIGH severity with an EPSS score of 0.00132 (Apache Advisory, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the listHostTags API endpoint does not enforce domain-scoped access control when called by a Domain Admin. By default, Domain Admins are permitted to invoke listHostTags, but the API lacks logic to filter results to only the hosts dedicated to the caller's domain, returning host tag data for every host in the CloudStack environment instead. No authentication bypass is required — the attacker only needs a valid Domain Admin account and the ability to call the API. No public proof-of-concept or technical write-up beyond the advisory is currently available (Apache Advisory, GitHub Advisory).
A Domain Admin can exploit this vulnerability to enumerate host tags for all physical or virtual hosts across the entire CloudStack deployment, including hosts belonging to other domains. This exposes infrastructure metadata that could aid in reconnaissance, revealing host capabilities, resource pools, or organizational topology beyond the attacker's authorized scope. While this vulnerability does not directly enable code execution or data destruction, the unauthorized disclosure of host configuration metadata could facilitate further targeted attacks or privilege escalation within a multi-tenant cloud environment (Apache Advisory, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time. The EPSS score is 0.00132, indicating a low probability of exploitation in the near term. The vulnerability requires an authenticated Domain Admin account, which limits the attack surface to privileged but potentially untrusted users in multi-tenant deployments. CVE-2026-66721 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Apache Advisory, GitHub Advisory).
listHostTags endpoint, e.g., GET /client/api?command=listHostTags&apiKey=<key>&signature=<sig>.listHostTags API calls from Domain Admin accounts, particularly if the volume of calls is unusual or originates from unexpected IP addresses./client/api?command=listHostTags) from Domain Admin sessions that do not correspond to routine administrative activity.Apache CloudStack users should upgrade to version 4.20.3.1 or 4.22.1.1 (or later), which enforce proper domain-scoped authorization on the listHostTags API. Until patching is possible, administrators should restrict Domain Admin API access, implement additional network-level controls to limit access to the CloudStack management API, and monitor listHostTags API usage for anomalous activity. ShapeBlue has also published a security advisory covering these fixes (Apache Advisory, ShapeBlue Advisory).
ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a corresponding security advisory covering the fixes in versions 4.20.3.1 and 4.22.1.1. The Apache Software Foundation announced the security releases via the Apache announcement mailing list. No significant broader media coverage or notable researcher commentary beyond the official advisory channels has been observed at this time (ShapeBlue Advisory, Apache Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."