Apache · Cloudstack · CVE-2026-61397
**Name of the Vulnerable Software and Affected Versions**
Apache CloudStack versions 4.19.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
**Description**
Exposure of sensitive information to an unauthorized actor occurs within the OAuth2 authentication plugin and Google OAuth integration.
**Recommendations**
Upgrade Apache CloudStack versions 4.19.0.0 through 4.20.3.0 to version 4.20.3.1.
Upgrade Apache CloudStack versions 4.21.0.0 through 4.22.1.0 to version 4.22.1.1.