CVE-2026-66797
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2026-66797 is an improper access control vulnerability in Apache CloudStack's annotation functionality that allows any authenticated user to create unauthorized annotations and disclose existing annotations on entities they do not own. The flaw affects Apache CloudStack versions 4.15.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. It was first reported on August 11, 2026, with the official Apache security advisory published on August 21, 2026. The vulnerability carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, Apache Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) and CWE-284 (Improper Access Control). The addAnnotation and listAnnotation APIs in Apache CloudStack perform an ownership check when an entity's UUID is provided, but critically fail to enforce the result of that check — meaning the authorization decision is computed but then ignored. As a result, any authenticated user can supply an arbitrary entity UUID to write annotations to or read existing annotations from resources they do not own, effectively bypassing tenant isolation controls (GitHub Advisory, Apache Advisory).

Impact

Successful exploitation allows any authenticated CloudStack user to read sensitive annotations or comments attached to cloud infrastructure entities (such as VMs, networks, or accounts) belonging to other tenants or administrators, and to inject unauthorized annotations into those resources. This represents a cross-tenant confidentiality and integrity breach within the cloud management plane, potentially exposing operational metadata, configuration notes, or credentials stored in annotations. The CVSS scope is marked as Changed, reflecting the ability to impact resources beyond the attacker's own security domain (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the advisory publication date (Apache Advisory). The vulnerability requires valid authentication credentials, which limits the attack surface to existing CloudStack users. The EPSS score is approximately 0.0018 (0.18%), indicating a low probability of near-term exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Authenticate: Obtain valid credentials for any user account on the target Apache CloudStack instance (versions 4.15.0.0–4.20.3.0 or 4.21.0.0–4.22.1.0).
  2. Enumerate entity UUIDs: Identify the UUID of a target entity (e.g., a VM, network, or account) owned by another user or tenant. UUIDs may be discoverable through CloudStack's list APIs or by observing shared infrastructure.
  3. Call addAnnotation API: Issue an authenticated API request to the addAnnotation endpoint, supplying the target entity's UUID. Despite the ownership check being performed, the result is not enforced, so the annotation is written successfully.
  4. Call listAnnotation API: Issue an authenticated API request to the listAnnotation endpoint with the target entity's UUID to retrieve all existing annotations/comments on that entity, potentially exposing sensitive operational data.
  5. Exfiltrate or manipulate data: Use the disclosed annotations for reconnaissance (e.g., credentials, configuration details) or inject misleading/malicious annotations to disrupt operations (GitHub Advisory, Apache Advisory).

Indicators of compromise

  • Logs: CloudStack API audit logs showing addAnnotation or listAnnotation API calls from a user account against entity UUIDs that do not belong to that user's account or domain.
  • Logs: Unusual volume of annotation API calls from a single authenticated user, particularly targeting multiple distinct entity UUIDs across different tenants or domains.
  • Network: API requests to CloudStack management server endpoints for annotation operations originating from unexpected source IPs or at unusual times.
  • Application: Presence of unexpected or anomalous annotation entries on cloud entities (VMs, networks, accounts) that were not created by the entity owner.

Mitigation and workarounds

Apache CloudStack has released patched versions 4.20.3.1 and 4.22.1.1 that correctly enforce the ownership check result in the addAnnotation and listAnnotation APIs. All users running affected versions (4.15.0.0–4.20.3.0 or 4.21.0.0–4.22.1.0) are strongly recommended to upgrade immediately. No configuration-based workaround is available; upgrading to a fixed version is the only remediation (Apache Advisory, GitHub Advisory).

Community reactions

ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the fixes included in CloudStack 4.20.3.1 and 4.22.1.1 (ShapeBlue Advisory). The vulnerability was also announced via the Apache announcement mailing list. No significant broader media coverage or notable researcher commentary beyond the vendor ecosystem has been observed.

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59654MEDIUM6.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66797MEDIUM5.4
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-68745NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66722NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66721NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management