Description
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.

This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

The Apache CloudStack webhook module contains a Server‑Side Request Forgery flaw that allows an attacker to force the CloudStack instance to send HTTP requests to arbitrary URLs. This can expose internal services, leak sensitive data, or enable further lateral movement within the network. No evidence of privilege escalation or code execution has been presented; the primary impact is the ability to read or write to internal resources through outbound requests. Based on the description, it is inferred that exploiting the flaw requires the attacker to trigger a webhook delivery request, which typically demands access to the CloudStack API or the ability to configure webhook definitions.

Affected Systems

Apache CloudStack versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. Systems running any of these releases are vulnerable until they upgrade to 4.20.3.1, 4.22.1.1, or a later release that incorporates the fix.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity, and the EPSS score of < 1% suggests that, while the probability of an exploit occurring is low, the potential impact is significant. The vulnerability is not listed in the CISA KEV catalog, but because the attack requires only webhook delivery requests, it can be executed by any actor who can submit webhook payloads or activate existing webhook definitions. The SSRF weakness permits internal network enumeration and data exfiltration, making it a critical risk for environments where CloudStack APIs are exposed or where webhooks are not strictly controlled.

Generated by OpenCVE AI on August 26, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify whether the installed Apache CloudStack version falls within the vulnerable range, 4.20.0.0–4.20.3.0 or 4.21.0.0–4.22.1.0.
  • Upgrade the CloudStack deployment to version 4.20.3.1, 4.22.1.1, or a newer release that contains the SSRF fix.
  • After the upgrade, verify that no new or existing webhook endpoint can reach internal services without proper authorization before returning the system to production.

Generated by OpenCVE AI on August 26, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module
Weaknesses CWE-918
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T19:25:43.874Z

Reserved: 2026-07-02T11:35:56.933Z

Link: CVE-2026-59085

cve-icon Vulnrichment

Updated: 2026-08-25T19:25:39.156Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:38.410

Modified: 2026-08-27T00:38:57.177

Link: CVE-2026-59085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)