Description
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.

This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑tenant unauthorized manipulation of Kubernetes clusters via the CloudStack CKS plugin
Action: Immediate Patch
AI Analysis

Impact

Apache CloudStack’s Kubernetes Service (CKS) plugin allows an authenticated attacker from one tenant to add or remove nodes in another tenant’s Kubernetes cluster. This flaw bypasses normal access controls and enables the attacker to alter cluster configuration, potentially disrupting services or gaining persistence on cluster nodes. The vulnerability is an instance of improper access control (CWE‑284).

Affected Systems

Vulnerable installations include Apache CloudStack versions 4.21.0.0 through 4.22.1.0. Any environment using the CKS plugin within this range is at risk; any system that has exposed the required administrative interfaces could be exploited.

Risk and Exploitability

The flaw permits an attacker to influence cluster state without local node access, representing a significant compromise of configuration integrity and availability. The CVE data does not mention publicly available exploit code; the EPSS score is < 1%, indicating a very low probability of exploitation, while the CVSS score of 9.1 signals a severe vulnerability. However, because the attack only requires authorization within one tenant, the potential domain of exploitation expands across all tenants sharing the CKS service. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate remediation.

Generated by OpenCVE AI on August 26, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache CloudStack to version 4.22.1.1 or later, which removes the unauthorized manipulation flaw.
  • If an upgrade is not immediately possible, limit access to the CKS management endpoints by implementing network segmentation or firewall rules so that only privileged administrators can reach them.
  • Review and tighten role‑based access controls for CKS operations, ensuring that only users in the intended tenant can perform node addition or removal actions.

Generated by OpenCVE AI on August 26, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache cloudstack
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
Vendors & Products Apache cloudstack

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Cloudstack
Vendors & Products Apache
Apache apache Cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation
Weaknesses CWE-284
References

Subscriptions

Apache Apache Cloudstack Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T19:20:14.393Z

Reserved: 2026-07-14T14:34:44.941Z

Link: CVE-2026-62440

cve-icon Vulnrichment

Updated: 2026-08-25T19:20:07.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:39.963

Modified: 2026-08-27T14:36:24.260

Link: CVE-2026-62440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:45:03Z

Weaknesses