
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-68745 is a SAML authentication bypass vulnerability in Apache CloudStack caused by certificate validation failures, allowing a malicious agent to forge SAML responses to the management server. It affects Apache CloudStack versions 4.5.2 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 on all platforms. The vulnerability was disclosed on August 21, 2026, with patches released the same day. It is classified as HIGH severity with an EPSS score of approximately 0.00075 (Apache Advisory, GitHub Advisory).
The root cause is improper verification of cryptographic signatures (CWE-347) in the SAML authentication flow of Apache CloudStack's management server. An attacker must first either spoof the IP address of the configured Identity Provider (IdP) or register a URL of their own choosing in the management server's IdP configuration. Once either precondition is met, the attacker can craft and submit a forged SAML response with invalid or self-signed signatures that the management server fails to properly validate, resulting in successful authentication. This maps to CAPEC-475 (Signature Spoofing by Improper Validation) (Apache Advisory, GitHub Advisory).
Successful exploitation allows a malicious agent to bypass SAML-based authentication entirely and log into Apache CloudStack with arbitrary user privileges, including potentially administrative access. This could lead to full compromise of the cloud infrastructure managed by the CloudStack instance, enabling unauthorized VM provisioning, data access, configuration changes, and lateral movement across tenant environments. The impact is limited to deployments with SAML authentication enabled (Apache Advisory, GitHub Advisory).
There is no public proof-of-concept exploit available and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.00075, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a precondition — either network-level IP spoofing of the IdP or the ability to register a malicious URL in the management server — which raises the bar for opportunistic attackers (Apache Advisory, GitHub Advisory).
Apache has released patched versions 4.20.3.1 and 4.22.1.1 to address this vulnerability; users should upgrade immediately. As interim mitigations, administrators should implement network segmentation to restrict access to the management server, particularly limiting which hosts can reach the SAML ACS endpoint. Additionally, review and validate all registered Identity Provider URLs in the CloudStack configuration to ensure only legitimate IdP URLs are present. Disabling SAML authentication until patching is feasible may be considered in high-risk environments (Apache Advisory, GitHub Advisory).
ShapeBlue, a major Apache CloudStack contributor and managed service provider, published a security advisory covering the fixes in versions 4.20.3.1 and 4.22.1.1 shortly after the Apache disclosure. The vulnerability was also announced via the Apache announce mailing list. No significant broader media coverage or notable researcher commentary beyond the vendor ecosystem has been identified at this time (ShapeBlue Advisory, Apache Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."