Description
Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack.




A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check only confirms the caller is a Domain Admin, without verifying whether the target project belongs to their domain or subdomain. This allows a malicious Domain Admin to tamper with project roles and permissions across unrelated domains.




This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.





Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Published: 2026-08-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass allowing domain admins to modify project roles across unrelated domains.
Action: Immediate Patch
AI Analysis

Impact

Improper authorization checks enable a Domain Admin to create, update, delete, and list project roles and permissions for any project, regardless of its domain affiliation. This flaw permits a malicious admin to tamper with role definitions and permissions that should be confined to their own domain, effectively granting unauthorized influence over projects in unrelated domains. The weakness corresponds to improper authorization (CWE‑285).

Affected Systems

Vulnerable versions of Apache CloudStack range from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The product is maintained by the Apache Software Foundation.

Risk and Exploitability

The EPSS score is 0.00132, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, so public exploitation data is limited. The flaw requires valid Domain Admin credentials, meaning that an attacker must either compromise such an account or be a legitimate admin. Once authenticated, the attacker can manipulate any project role or permission, raising the risk of privilege escalation, data leakage, and denial of service for affected projects. Given the EPSS score of 0.00132 indicates a very low exploitation probability, the likelihood of exploitation remains low, but it cannot be fully discounted.

Generated by OpenCVE AI on August 24, 2026 at 19:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache CloudStack to 4.20.3.1 or 4.22.1.1 or later, which contains the fix for the authorization issue.
  • If an upgrade is not immediately feasible, enforce least‑privilege by reviewing and tightening Domain Admin rights, and audit the use of project‑role APIs to detect suspicious activity.
  • Add application‑level checks or cross‑domain verification for project‑role operations, and enable detailed logging of role modifications to provide forensic traceability.

Generated by OpenCVE AI on August 24, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Fri, 21 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cloudstack
Vendors & Products Apache
Apache cloudstack

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check only confirms the caller is a Domain Admin, without verifying whether the target project belongs to their domain or subdomain. This allows a malicious Domain Admin to tamper with project roles and permissions across unrelated domains. This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Title Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue
Weaknesses CWE-285
References

Subscriptions

Apache Cloudstack
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-25T03:56:49.706Z

Reserved: 2026-07-27T15:21:12.522Z

Link: CVE-2026-66722

cve-icon Vulnrichment

Updated: 2026-08-24T16:59:24.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-21T09:16:40.460

Modified: 2026-08-27T13:59:28.220

Link: CVE-2026-66722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:00:04Z

Weaknesses