Apache · Cloudstack · CVE-2026-59655
**Name of the Vulnerable Software and Affected Versions**
Apache CloudStack versions 4.19.0.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
**Description**
An issue in the OAuth authentication plugin occurs while listing OAuth providers, leading to the exposure of sensitive information to unauthorized actors.
**Recommendations**
Upgrade Apache CloudStack versions 4.19.0.0 through 4.20.3.0 to version 4.20.3.1 or later.
Upgrade Apache CloudStack versions 4.21.0.0 through 4.22.1.0 to version 4.22.1.1 or later.