Impact
Improper privilege management in the Two‑factor authentication plugin allows a user lacking sufficient privileges to disable the two‑factor authentication enforcement. This flaw effectively lets an attacker bypass MFA and gain elevated access to the system, compromising confidentiality and integrity of protected resources. The weakness is identified as CWE‑269.
Affected Systems
Apache CloudStack editions from 4.18.0.0 up to and including 4.20.3.0, and from 4.21.0.0 up to and including 4.22.1.0, are affected.
Risk and Exploitability
The vulnerability can be exploited by an authenticated user who can submit a request to disable two‑factor authentication but is not subject to proper privilege checks, allowing removal of MFA protections. The flaw carries a CVSS score of 8.8. The EPSS score is 0.00182, indicating a very low probability of exploitation but still possible. The issue is not listed in the CISA KEV catalog, so no exploitation reports from that source. Patch releases are available, and there is no official workaround, so upgrading immediately is the advised action.
OpenCVE Enrichment