Impact
WebVirtCloud fails to verify permission flags, enabling a user with only read‑only access to perform privileged actions such as powering off VMs, resetting root passwords, installing SSH keys, and managing ISO images. This flaw represents missing authorization (CWE-862), which can lead to unauthorized control over virtual instances. The consequence is a significant elevation of privileges, allowing an attacker to effectively take over or disrupt virtual machines.
Affected Systems
The flaw affects the WebVirtCloud application maintained by retspen. No specific version range is included in the public material; users should check the vendor’s release notes or repository for affected releases. Without version information, all deployments of the current code base until the fix are potentially vulnerable.
Risk and Exploitability
With a CVSS score of 8.7 the issue is considered high severity. The EPSS is below 1 %, indicating that current exploitation data for this vulnerability is sparse, and it is not listed in CISA’s KEV catalog. The likely attack vector requires a user to be authenticated with read‑only privileges and to interact with WebVirtCloud’s web interface, where the get_instance gate accepts any existing grant without checking its type. Because the privilege escalation is available only after authentication, an attacker who can compromise a read‑only account or leak credentials could use the web API to power off, reset, or otherwise manipulate virtual machines.
OpenCVE Enrichment