Description
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow.

This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Two‑Factor Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

Improper privilege management in the Two‑factor authentication plugin allows a user lacking sufficient privileges to disable the two‑factor authentication enforcement. This flaw effectively lets an attacker bypass MFA and gain elevated access to the system, compromising confidentiality and integrity of protected resources. The weakness is identified as CWE‑269.

Affected Systems

Apache CloudStack editions from 4.18.0.0 up to and including 4.20.3.0, and from 4.21.0.0 up to and including 4.22.1.0, are affected.

Risk and Exploitability

The vulnerability can be exploited by an authenticated user who can submit a request to disable two‑factor authentication but is not subject to proper privilege checks, allowing removal of MFA protections. The flaw carries a CVSS score of 8.8. The EPSS score is 0.00182, indicating a very low probability of exploitation but still possible. The issue is not listed in the CISA KEV catalog, so no exploitation reports from that source. Patch releases are available, and there is no official workaround, so upgrading immediately is the advised action.

Generated by OpenCVE AI on August 24, 2026 at 19:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade your Apache CloudStack installation to version 4.20.3.1, 4.22.1.1, or a later release that contains the fix.
  • Verify that disabling two‑factor authentication now requires administrative privileges by testing with a non‑admin account.
  • Review audit logs for any unauthorized attempts to disable two‑factor authentication and audit user permissions periodically.

Generated by OpenCVE AI on August 24, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow
Weaknesses CWE-269
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-24T15:58:06.019Z

Reserved: 2026-07-07T12:07:05.738Z

Link: CVE-2026-59799

cve-icon Vulnrichment

Updated: 2026-08-24T15:57:57.508Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:38.890

Modified: 2026-08-27T00:24:58.477

Link: CVE-2026-59799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T19:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management