Description
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality.

This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting through the instance reset-password UI allows arbitrary script execution in the browser of authenticated users
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from improper encoding or escaping of output when users perform the instance reset-password function in Apache CloudStack's web interface. If an attacker supplies malicious input that is reflected in the page without proper escaping, the browser will execute that input as script. The resulting cross-site scripting can be used to hij the victim's session, steal sensitive data, or perform further attacks against the CloudStack instance.

Affected Systems

Apache CloudStack releases from 4.15.1.0 through 4.20.3.0, and from 4.21.0.0 through 4.22.1.0, are affected. The Apache Software Foundation provides a fix in version 4.20.3.1 and 4.22.1.1, respectively, and any later release.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is the instance reset-password UI within the CloudStack web console. The vulnerability appears to require a user with authenticated access to the console who can trigger the reset-password functionality. Because the flaw allows arbitrary script execution when malicious input is reflected, an attacker who can influence the input can compromise the security of that user session. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the risk depends on internal threat models and the level of exposure of the UI. The CVSS score of 9.1 indicates a high severity rating.

Generated by OpenCVE AI on August 26, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache CloudStack 4.20.3.1, 4.22.1.1, or a later fixed release.
  • Restrict access to the instance reset-password UI to users with verified administrative rights.
  • Implement content security policy headers in the CloudStack web interface to mitigate reflected XSS.

Generated by OpenCVE AI on August 26, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI
Weaknesses CWE-116
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T19:21:10.214Z

Reserved: 2026-07-09T08:07:00.350Z

Link: CVE-2026-61398

cve-icon Vulnrichment

Updated: 2026-08-25T19:21:04.195Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:39.480

Modified: 2026-08-27T00:20:29.263

Link: CVE-2026-61398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:45:03Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output