Apache · Cloudstack · CVE-2026-47359
**Name of the Vulnerable Software and Affected Versions**
Apache CloudStack versions 4.20.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
**Description**
An OS Command Injection issue exists in the NAS backup provider plugin. The 'addBackupRepository' and 'updateBackupRepository' API endpoints accept unsanitized command options for the backup repository. A malicious operator account can exploit this to inject arbitrary commands that execute on the KVM hypervisor host when a backup restore is performed by any account.
**Recommendations**
Upgrade versions 4.20.0.0 through 4.20.3.0 to 4.20.3.1 or later.
Upgrade versions 4.21.0.0 through 4.22.1.0 to 4.22.1.1 or later.