Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration.

This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue.
Published: 2026-08-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade
AI Analysis

Impact

Apache CloudStack’s OAuth2 authentication plugin and Google OAuth integration contain an information disclosure flaw that can leak OAuth2 tokens across requests. Attackers who can read requests or responses may capture these tokens, potentially allowing them to impersonate users or gain unauthorized access to CloudStack resources. The weakness is a classic information disclosure (CWE‑200).

Affected Systems

The affected products are Apache CloudStack versions 4.19.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Users are encouraged to upgrade to version 4.20.3.1 or 4.22.1.1 to resolve the issue.

Risk and Exploitability

The EPSS score is < 1%, indicating a low current public exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog, which confirms no known widespread exploitation. Because tokens are transmitted over network traffic, the potential for an attacker to intercept them exists if traffic is not properly secured. The CVSS score is 7.5, which indicates a high severity and demonstrates a significant risk to confidentiality and the potential for an unauthenticated or low‑privileged user to acquire sensitive authentication tokens. The likely attack vector is through application‑level manipulation of OAuth2 requests and responses, inferred from the description of cross‑request leakage.

Generated by OpenCVE AI on August 25, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache CloudStack to 4.20.3.1 or 4.22.1.1, which includes a fix for the token leakage flaw.
  • If an immediate upgrade is not possible, disable or tightly restrict the OAuth2 integration or remove unnecessary Google OAuth identity providers until a patch is applied.
  • Actively monitor audit logs for abnormal token or authentication request patterns to detect potential leaks.

Generated by OpenCVE AI on August 25, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache cloudstack
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
Vendors & Products Apache cloudstack

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Cloudstack
Vendors & Products Apache
Apache apache Cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue.
Title Apache CloudStack: OAuth2 Token Cross-Request Leak
Weaknesses CWE-200
References

Subscriptions

Apache Apache Cloudstack Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T19:22:14.318Z

Reserved: 2026-07-09T07:56:59.890Z

Link: CVE-2026-61397

cve-icon Vulnrichment

Updated: 2026-08-25T19:21:59.466Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:39.363

Modified: 2026-08-27T00:21:49.233

Link: CVE-2026-61397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor