Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries.

This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of webhook delivery data
Action: Apply patch
AI Analysis

Impact

Apache CloudStack users can access or delete sensitive webhook delivery information because an access control check is omitted in the API handling of listing and deleting deliveries. This flaw leads to exposure of confidential data and loss of data integrity for the deliveries stored by the platform.

Affected Systems

The vulnerability affects Apache CloudStack provided by the Apache Software Foundation. The affected variants include version series 4.20.x from 4.20.0.0 through 4.20.3.0 and 4.21.x through 4.22.1.0.

Risk and Exploitability

The CVSS score is 4.3 and the EPSS score is < 1%, so the severity assessment relies on the potential confidentiality impact and the widespread presence across several release lines. Based on the description, it is inferred that an attacker can exploit the vulnerability by interacting with the webhook delivery management APIs over the network. The KEV catalog does not list active exploitation, yet the existence of the flaw across multiple releases suggests a non‑negligible risk and warrants immediate attention.

Generated by OpenCVE AI on August 24, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache CloudStack to version 4.20.3.1, 4.22.1.1 or later, which contains the fix for the access control issue.
  • Limit exposure of the webhook delivery API endpoints by restricting network access to trusted hosts or subnets, such as through firewall rules or a reverse proxy.
  • Review the authorization logic for the webhook delivery APIs and enforce role‑based access control so that only authorized users can list or delete deliveries.

Generated by OpenCVE AI on August 24, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Webhook Deliveries Incorrect Access
Weaknesses CWE-200
CWE-284
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-24T17:05:33.247Z

Reserved: 2026-07-22T11:23:32.148Z

Link: CVE-2026-65613

cve-icon Vulnrichment

Updated: 2026-08-24T17:05:25.971Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:40.207

Modified: 2026-08-27T14:04:56.210

Link: CVE-2026-65613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control