Description
Missing authorization issue for domain admins in CloudStack's host tags listing functionality.




Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain.




This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.




Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data exposure
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check allows domain administrators to call the listHostTags API and retrieve tags for all hosts in the CloudStack environment, not just those belonging to their own domain. This flaw denies proper domain scoping and enables privileged users to view potentially sensitive configuration information about hosts they are not supposed to have visibility on. The vulnerability primarily leads to data exposure and can facilitate further compromise by providing an attacker with a broader view of the infrastructure.

Affected Systems

Apache CloudStack versions 4.12.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. The fix is included in versions 4.20.3.1 and 4.22.1.1 and later, so users should upgrade to at least those releases.

Risk and Exploitability

The CVSS score of 2.7 indicates a low overall severity, but the EPSS score remains < 1% and it is not in CISA KEV, so the exact exploitation probability is still unknown. Domain administrators have legitimate API access, so the attack vector is an authenticated API call. Given the possibility of exposing sensitive tags, the risk remains low to moderate. No specific exploit code is documented, but domain admins with ordinary privileges could exploit it.

Generated by OpenCVE AI on August 24, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apache CloudStack to version 4.20.3.1 or 4.22.1.1, or any later release that includes the fix. This resolves the missing authorization check and limits host tag visibility to the administrator’s domain.
  • If immediate upgrade is not possible, temporarily disable or restrict the listHostTags API for domain administrators and enforce host scoping through custom access policies or API gateway rules.
  • Audit CI/CD pipelines and production systems to identify any instances running vulnerable versions and plan for migration to secure releases.

Generated by OpenCVE AI on August 24, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache cloudstack
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
Vendors & Products Apache cloudstack

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Cloudstack
Vendors & Products Apache
Apache apache Cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain. This issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: Authorization issue with listHostTags for domain admins
Weaknesses CWE-862
References

Subscriptions

Apache Apache Cloudstack Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-24T17:06:30.824Z

Reserved: 2026-07-27T15:02:58.111Z

Link: CVE-2026-66721

cve-icon Vulnrichment

Updated: 2026-08-24T17:06:23.270Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:40.327

Modified: 2026-08-27T14:00:16.193

Link: CVE-2026-66721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses