CVE-2026-66722
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2026-66722 is an improper authorization vulnerability affecting Apache CloudStack that allows Domain Admins to perform unauthorized CRUD operations on Project Roles and Project Role permissions across unrelated domains. The flaw was disclosed on August 21, 2026, and affects Apache CloudStack versions 4.15.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Patched versions 4.20.3.1 and 4.22.1.1 were released simultaneously with the advisory. The vulnerability is classified as HIGH severity with an EPSS score of approximately 0.0013 (Apache Advisory, GitHub Advisory).

Technical details

The root cause is CWE-285 (Improper Authorization): the authorization check for CRUD operations on Project Roles and Project Role permissions only verifies that the caller holds a Domain Admin role, without confirming that the target project belongs to the caller's domain or any of its subdomains. This missing scope validation allows a Domain Admin to invoke create, update, delete, and list operations against projects in entirely unrelated domains. No authentication bypass is required — the attacker must already possess a valid Domain Admin account, making this a privilege escalation/authorization bypass rather than an unauthenticated attack (Apache Advisory, GitHub Advisory).

Impact

A malicious Domain Admin can tamper with role-based access controls (RBAC) in projects belonging to other, unrelated domains — creating, modifying, or deleting project roles and their associated permissions without authorization. This undermines the multi-tenant isolation model of CloudStack, potentially allowing privilege escalation within targeted projects, unauthorized access grants to attacker-controlled accounts, or denial of access to legitimate project members. The integrity and confidentiality of cross-domain project configurations are directly at risk, and in a shared cloud environment, this could facilitate lateral movement between tenant domains (Apache Advisory, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.0013 (0.13%), indicating a low near-term exploitation probability. Exploitation requires an authenticated Domain Admin account, which limits the attack surface to insider threats or compromised privileged accounts. No threat actor attribution or CISA KEV catalog listing has been reported (Apache Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain Domain Admin credentials: The attacker must already possess or compromise a valid Domain Admin account in any domain within the Apache CloudStack deployment.
  2. Identify target projects in other domains: Use the CloudStack API or UI to enumerate projects across the platform. The listProjects API call, when issued by a Domain Admin, may return projects from other domains due to the same authorization gap.
  3. Perform unauthorized CRUD operations: Issue API calls such as createProjectRole, updateProjectRole, deleteProjectRole, listProjectRoles, createProjectRolePermission, updateProjectRolePermission, or deleteProjectRolePermission, supplying the ID of a project in an unrelated domain. The server will accept these requests because it only checks that the caller is a Domain Admin, not that the project is within their domain scope.
  4. Escalate privileges or disrupt access: Modify project roles to grant elevated permissions to attacker-controlled accounts within the target project, or delete legitimate roles to deny access to authorized users, achieving unauthorized control over cross-domain project resources (Apache Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: CloudStack management server logs (/var/log/cloudstack/management/management-server.log) showing Domain Admin accounts invoking createProjectRole, updateProjectRole, deleteProjectRole, createProjectRolePermission, updateProjectRolePermission, or deleteProjectRolePermission API calls against project IDs outside their own domain hierarchy.
  • Audit Trail: CloudStack event/audit logs recording project role or permission changes attributed to a Domain Admin user whose domain does not match the target project's domain.
  • Configuration: Unexpected project roles or permissions appearing in projects, or legitimate roles being deleted, particularly in domains not administered by the acting Domain Admin.
  • API Access Patterns: Unusual volume of project role management API calls from a single Domain Admin account, especially targeting multiple domains in a short time window.

Mitigation and workarounds

Apache CloudStack users should upgrade to version 4.20.3.1 (for the 4.20.x branch) or 4.22.1.1 (for the 4.22.x branch) or later, which contain the fix for this authorization bypass. As an interim measure, administrators should audit existing project role and permission configurations for unauthorized modifications made by Domain Admins outside their domain scope, and consider restricting Domain Admin privileges where possible. There are no documented configuration-only workarounds that fully mitigate the issue without patching (Apache Advisory, GitHub Advisory).

Community reactions

ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the fixes included in versions 4.20.3.1 and 4.22.1.1 on the same day as the Apache disclosure (ShapeBlue Advisory). The vulnerability was also announced on the Apache announcements mailing list. No significant broader media coverage or notable researcher commentary beyond the vendor ecosystem has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59654MEDIUM6.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66797MEDIUM5.4
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-68745NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66722NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66721NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management