Apache · Cloudstack · CVE-2026-66722
**Name of the Vulnerable Software and Affected Versions**
Apache CloudStack versions 4.15.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
**Description**
Improper authorization exists for CRUD (Create, Read, Update, Delete) operations on Project Roles and Project Role permissions for domain admins. A Domain Admin can create, update, delete, and list project roles and permissions for projects in any domain, regardless of whether the project belongs to their own domain or subdomain. The system only verifies that the caller is a Domain Admin but fails to validate the ownership of the target project, allowing a malicious Domain Admin to tamper with roles and permissions across unrelated domains.
**Recommendations**
Upgrade versions 4.15.0.0 through 4.20.3.0 to version 4.20.3.1 or later.
Upgrade versions 4.21.0.0 through 4.22.1.0 to version 4.22.1.1 or later.