CVE-2026-68745
Apache CloudStack vulnerability analysis and mitigation

Overview

CVE-2026-68745 is a SAML authentication bypass vulnerability in Apache CloudStack caused by certificate validation failures, allowing a malicious agent to forge SAML responses to the management server. It affects Apache CloudStack versions 4.5.2 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 on all platforms. The vulnerability was disclosed on August 21, 2026, with patches released the same day. It is classified as HIGH severity with an EPSS score of approximately 0.00075 (Apache Advisory, GitHub Advisory).

Technical details

The root cause is improper verification of cryptographic signatures (CWE-347) in the SAML authentication flow of Apache CloudStack's management server. An attacker must first either spoof the IP address of the configured Identity Provider (IdP) or register a URL of their own choosing in the management server's IdP configuration. Once either precondition is met, the attacker can craft and submit a forged SAML response with invalid or self-signed signatures that the management server fails to properly validate, resulting in successful authentication. This maps to CAPEC-475 (Signature Spoofing by Improper Validation) (Apache Advisory, GitHub Advisory).

Impact

Successful exploitation allows a malicious agent to bypass SAML-based authentication entirely and log into Apache CloudStack with arbitrary user privileges, including potentially administrative access. This could lead to full compromise of the cloud infrastructure managed by the CloudStack instance, enabling unauthorized VM provisioning, data access, configuration changes, and lateral movement across tenant environments. The impact is limited to deployments with SAML authentication enabled (Apache Advisory, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit available and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.00075, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a precondition — either network-level IP spoofing of the IdP or the ability to register a malicious URL in the management server — which raises the bar for opportunistic attackers (Apache Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Apache CloudStack management servers running versions 4.5.2–4.20.3.0 or 4.21.0.0–4.22.1.0 with SAML authentication enabled by probing the management server's login page or API endpoints for SAML-related parameters.
  2. Establish precondition: Either (a) perform IP spoofing to impersonate the configured Identity Provider's IP address on the network, or (b) find a way to register a malicious IdP URL in the CloudStack management server configuration (e.g., via a misconfigured admin interface or social engineering).
  3. Craft forged SAML response: Construct a SAML response XML document asserting the desired user identity and privileges, signed with an attacker-controlled or self-signed certificate that the vulnerable CloudStack instance will not properly validate.
  4. Submit forged response: Send the crafted SAML response to the CloudStack management server's SAML assertion consumer service (ACS) endpoint, impersonating a legitimate IdP response.
  5. Gain unauthorized access: The management server, failing to verify the cryptographic signature, accepts the forged SAML assertion and grants the attacker login access with the privileges specified in the forged response (Apache Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected SAML assertion consumer service (ACS) POST requests originating from IP addresses not matching the configured Identity Provider; traffic from unknown sources to the CloudStack management server's SAML endpoint.
  • Logs: CloudStack management server logs showing successful SAML authentication events from unexpected or unrecognized IdP URLs or IP addresses; authentication events for privileged accounts without corresponding IdP-side session records.
  • Configuration: Presence of unrecognized or unauthorized IdP URLs registered in the CloudStack SAML configuration; recent changes to IdP URL settings not initiated by administrators.
  • Process/Session: Unexpected administrative sessions or API activity following SAML login events, particularly account creation, VM provisioning, or configuration changes by accounts not previously active (Apache Advisory).

Mitigation and workarounds

Apache has released patched versions 4.20.3.1 and 4.22.1.1 to address this vulnerability; users should upgrade immediately. As interim mitigations, administrators should implement network segmentation to restrict access to the management server, particularly limiting which hosts can reach the SAML ACS endpoint. Additionally, review and validate all registered Identity Provider URLs in the CloudStack configuration to ensure only legitimate IdP URLs are present. Disabling SAML authentication until patching is feasible may be considered in high-risk environments (Apache Advisory, GitHub Advisory).

Community reactions

ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the fixes in versions 4.20.3.1 and 4.22.1.1 shortly after the Apache disclosure. The vulnerability was also announced via the Apache announce mailing list. No significant broader media coverage or notable researcher commentary beyond the vendor ecosystem has been identified at this time (ShapeBlue Advisory, Apache Announce).

Additional resources


SourceThis report was generated using AI

Related Apache CloudStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59654MEDIUM6.8
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66797MEDIUM5.4
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-68745NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66722NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026
CVE-2026-66721NONEN/A
  • Apache CloudStack logoApache CloudStack
  • cpe:2.3:a:apache:cloudstack
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management