Apache · Cloudstack · CVE-2026-50112
**Name of the Vulnerable Software and Affected Versions**
Apache CloudStack versions 4.14.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
**Description**
An authenticated tenant can perform Server-Side Request Forgery (SSRF) by registering a template that points to a malicious metalink file containing internal targets, allowing the Secondary Storage VM to retrieve and persist this data. Additionally, a tenant with the default User role can achieve Remote Code Execution (RCE) as root on the KVM hypervisor host. This occurs when a user registers a VM template with the `directDownload` variable set to true and a URL pointing to a .metalink file; the management server fetches the XML and dispatches the download to the KVM agent without re-validating the inner URLs against the scheme allowlist.
**Recommendations**
For versions 4.14.0.0 through 4.20.3.0, upgrade to version 4.20.3.1 or later.
For versions 4.21.0.0 through 4.22.1.0, upgrade to version 4.22.1.1 or later.