CRITICAL🇵🇱 Wersja polska

CVE-2026-25199

CVSS 9.1v3.1pub. 2026-05-08upd. 2026-05-09

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable instance setting, proxmox_vmid, to associate CloudStack instances with Proxmox virtual machines. Because this value is not restricted or validated against tenant ownership and Proxmox VM IDs are predictable, a non-privileged attacker can modify the setting to reference a VM belonging to another account. This allows unauthorized cross-tenant access and enables full control over the targeted VM, including starting, stopping, and destroying the virtual machine. Users are recommended to upgrade to version 4.22.0.1, which fixes this issue. As a workaround for the existing installations, editing of the proxmox_vmid instance detail by users can be prevented by adding this detail name to the global configuration parameter - user.vm.denied.details.

🤖 AI Analysis
How it works

The Proxmox extension for CloudStack uses a user-editable instance parameter named proxmox_vmid to associate CloudStack instances with Proxmox virtual machines. This parameter is not validated for resource ownership by the tenant nor is it restricted from editing. Since VM identifiers in Proxmox are predictable, an unprivileged attacker can modify the proxmox_vmid value to point to a virtual machine belonging to another account. As a result, the attacker gains full control over the target virtual machine, including the ability to run, stop, and destroy it.

Impact

An attacker can gain unauthorized access to instances of other tenants and take full operational control over them — including running, stopping, and permanently deleting virtual machines. Both confidentiality and integrity of other users' data and resources are compromised.

Mitigation & patch

It is recommended to update to version 4.22.0.1, which eliminates the vulnerability. As a workaround for existing installations, the proxmox_vmid parameter name should be added to the global user.vm.denied.details configuration, which will prevent users from editing this field.

Who is affected

Apache CloudStack in versions from 4.21.0.0 to 4.22.0.0 (inclusive) in deployments using the Proxmox extension

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Cloudstack

    APP
    Apache
    4.21.0.0 – 4.22.0.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-62440CRITICAL9.1same product

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-t...

CVE-2026-61398CRITICAL9.1same product

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Pas...

CVE-2026-59085CRITICAL9.1same product

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhoo...

CVE-2024-39864CRITICAL9.8PL ✓same product

Apache CloudStack — RCE przez niechroniony port integracyjny API

CVE-2024-38346CRITICAL9.8PL ✓same product

Apache CloudStack — RCE przez nieuwierzytelniony port klastra (9090)