
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66722 is an improper authorization vulnerability affecting Apache CloudStack that allows Domain Admins to perform unauthorized CRUD operations on Project Roles and Project Role permissions across unrelated domains. The flaw was disclosed on August 21, 2026, and affects Apache CloudStack versions 4.15.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Patched versions 4.20.3.1 and 4.22.1.1 were released simultaneously with the advisory. The vulnerability is classified as HIGH severity with an EPSS score of approximately 0.0013 (Apache Advisory, GitHub Advisory).
The root cause is CWE-285 (Improper Authorization): the authorization check for CRUD operations on Project Roles and Project Role permissions only verifies that the caller holds a Domain Admin role, without confirming that the target project belongs to the caller's domain or any of its subdomains. This missing scope validation allows a Domain Admin to invoke create, update, delete, and list operations against projects in entirely unrelated domains. No authentication bypass is required — the attacker must already possess a valid Domain Admin account, making this a privilege escalation/authorization bypass rather than an unauthenticated attack (Apache Advisory, GitHub Advisory).
A malicious Domain Admin can tamper with role-based access controls (RBAC) in projects belonging to other, unrelated domains — creating, modifying, or deleting project roles and their associated permissions without authorization. This undermines the multi-tenant isolation model of CloudStack, potentially allowing privilege escalation within targeted projects, unauthorized access grants to attacker-controlled accounts, or denial of access to legitimate project members. The integrity and confidentiality of cross-domain project configurations are directly at risk, and in a shared cloud environment, this could facilitate lateral movement between tenant domains (Apache Advisory, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.0013 (0.13%), indicating a low near-term exploitation probability. Exploitation requires an authenticated Domain Admin account, which limits the attack surface to insider threats or compromised privileged accounts. No threat actor attribution or CISA KEV catalog listing has been reported (Apache Advisory, GitHub Advisory).
listProjects API call, when issued by a Domain Admin, may return projects from other domains due to the same authorization gap.createProjectRole, updateProjectRole, deleteProjectRole, listProjectRoles, createProjectRolePermission, updateProjectRolePermission, or deleteProjectRolePermission, supplying the ID of a project in an unrelated domain. The server will accept these requests because it only checks that the caller is a Domain Admin, not that the project is within their domain scope./var/log/cloudstack/management/management-server.log) showing Domain Admin accounts invoking createProjectRole, updateProjectRole, deleteProjectRole, createProjectRolePermission, updateProjectRolePermission, or deleteProjectRolePermission API calls against project IDs outside their own domain hierarchy.Apache CloudStack users should upgrade to version 4.20.3.1 (for the 4.20.x branch) or 4.22.1.1 (for the 4.22.x branch) or later, which contain the fix for this authorization bypass. As an interim measure, administrators should audit existing project role and permission configurations for unauthorized modifications made by Domain Admins outside their domain scope, and consider restricting Domain Admin privileges where possible. There are no documented configuration-only workarounds that fully mitigate the issue without patching (Apache Advisory, GitHub Advisory).
ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the fixes included in versions 4.20.3.1 and 4.22.1.1 on the same day as the Apache disclosure (ShapeBlue Advisory). The vulnerability was also announced on the Apache announcements mailing list. No significant broader media coverage or notable researcher commentary beyond the vendor ecosystem has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."