PT-2026-38914 · Unknown · Cloudstack
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2025-66171
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CloudStack versions 4.21.0.0 through 4.22.0.0
Description
The CloudStack Backup plugin contains improper access logic. Authenticated users in environments where this plugin is enabled can leverage specific APIs to create new virtual machines using backups belonging to any other user in the environment.
Recommendations
Upgrade to CloudStack version 4.22.0.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudstack