CVE-2026-66721
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2026-66721 is a missing authorization vulnerability in Apache CloudStack's listHostTags API that allows Domain Admins to retrieve host tags for all hosts across the entire environment, rather than being restricted to hosts dedicated to their own domain. It affects Apache CloudStack versions 4.12.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The vulnerability was disclosed on August 21, 2026, with patches available in versions 4.20.3.1 and 4.22.1.1. It is classified as HIGH severity with an EPSS score of 0.00132 (Apache Advisory, GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the listHostTags API endpoint does not enforce domain-scoped access control when called by a Domain Admin. By default, Domain Admins are permitted to invoke listHostTags, but the API lacks logic to filter results to only the hosts dedicated to the caller's domain, returning host tag data for every host in the CloudStack environment instead. No authentication bypass is required — the attacker only needs a valid Domain Admin account and the ability to call the API. No public proof-of-concept or technical write-up beyond the advisory is currently available (Apache Advisory, GitHub Advisory).

Impact

A Domain Admin can exploit this vulnerability to enumerate host tags for all physical or virtual hosts across the entire CloudStack deployment, including hosts belonging to other domains. This exposes infrastructure metadata that could aid in reconnaissance, revealing host capabilities, resource pools, or organizational topology beyond the attacker's authorized scope. While this vulnerability does not directly enable code execution or data destruction, the unauthorized disclosure of host configuration metadata could facilitate further targeted attacks or privilege escalation within a multi-tenant cloud environment (Apache Advisory, GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time. The EPSS score is 0.00132, indicating a low probability of exploitation in the near term. The vulnerability requires an authenticated Domain Admin account, which limits the attack surface to privileged but potentially untrusted users in multi-tenant deployments. CVE-2026-66721 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Apache Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain Domain Admin credentials: Acquire or use an existing Domain Admin account within the target Apache CloudStack environment (versions 4.12.0.0–4.20.3.0 or 4.21.0.0–4.22.1.0).
  2. Authenticate to the CloudStack API: Use the CloudStack API or management UI to authenticate and obtain a valid API key and secret for the Domain Admin account.
  3. Call the listHostTags API: Issue an authenticated API request to the listHostTags endpoint, e.g., GET /client/api?command=listHostTags&apiKey=<key>&signature=<sig>.
  4. Retrieve unrestricted host tag data: The API returns host tags for all hosts in the environment without domain scoping, exposing infrastructure metadata beyond the Domain Admin's authorized domain (Apache Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: CloudStack API access logs showing listHostTags API calls from Domain Admin accounts, particularly if the volume of calls is unusual or originates from unexpected IP addresses.
  • Network: API requests to the CloudStack management server's API endpoint (/client/api?command=listHostTags) from Domain Admin sessions that do not correspond to routine administrative activity.
  • Behavioral: A Domain Admin account querying host tag data for hosts outside their assigned domain, which may appear as anomalous cross-domain API activity in audit logs (Apache Advisory).

Mitigation and workarounds

Apache CloudStack users should upgrade to version 4.20.3.1 or 4.22.1.1 (or later), which enforce proper domain-scoped authorization on the listHostTags API. Until patching is possible, administrators should restrict Domain Admin API access, implement additional network-level controls to limit access to the CloudStack management API, and monitor listHostTags API usage for anomalous activity. ShapeBlue has also published a security advisory covering these fixes (Apache Advisory, ShapeBlue Advisory).

Community reactions

ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a corresponding security advisory covering the fixes in versions 4.20.3.1 and 4.22.1.1. The Apache Software Foundation announced the security releases via the Apache announcement mailing list. No significant broader media coverage or notable researcher commentary beyond the official advisory channels has been observed at this time (ShapeBlue Advisory, Apache Announce).

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59654MEDIUM6.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66797MEDIUM5.4
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-68745NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66722NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66721NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management