Impact
Apache CloudStack’s Kubernetes Service (CKS) plugin allows an authenticated attacker from one tenant to add or remove nodes in another tenant’s Kubernetes cluster. This flaw bypasses normal access controls and enables the attacker to alter cluster configuration, potentially disrupting services or gaining persistence on cluster nodes. The vulnerability is an instance of improper access control (CWE‑284).
Affected Systems
Vulnerable installations include Apache CloudStack versions 4.21.0.0 through 4.22.1.0. Any environment using the CKS plugin within this range is at risk; any system that has exposed the required administrative interfaces could be exploited.
Risk and Exploitability
The flaw permits an attacker to influence cluster state without local node access, representing a significant compromise of configuration integrity and availability. The CVE data does not mention publicly available exploit code; the EPSS score is < 1%, indicating a very low probability of exploitation, while the CVSS score of 9.1 signals a severe vulnerability. However, because the attack only requires authorization within one tenant, the potential domain of exploitation expands across all tenants sharing the CKS service. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate remediation.
OpenCVE Enrichment