Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers.

This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An unauthenticated user can retrieve OAuth client secrets by listing providers in Apache CloudStack, exposing sensitive information that could be used to compromise authentication flows. This flaw corresponds to CWE‑200 and enables an attacker to gain credentials that may lead to further exploitation.

Affected Systems

Apache Software Foundation’s Apache CloudStack versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0 are vulnerable when the OAuth authentication plugin is enabled and the provider list endpoint is accessed without authentication.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 7.5. The likely attack vector is an unauthenticated HTTP request to the provider listing API, which yields client secrets. While the flaw alone does not grant code execution, the disclosure of sensitive credentials is a significant confidentiality risk and could enable further attacks in the environment.

Generated by OpenCVE AI on August 25, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache CloudStack version 4.20.3.1 or 4.22.1.1 or later, which contains the fix
  • Regenerate all OAuth client secrets after the upgrade to eliminate any compromised values
  • Restrict access to the OAuth provider configuration endpoints with network segmentation or firewall rules to prevent unauthorized listing

Generated by OpenCVE AI on August 25, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure
Weaknesses CWE-200
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T19:24:58.263Z

Reserved: 2026-07-06T09:08:57.444Z

Link: CVE-2026-59655

cve-icon Vulnrichment

Updated: 2026-08-25T19:24:36.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:38.533

Modified: 2026-08-27T00:34:11.930

Link: CVE-2026-59655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor