PT-2026-79326 · Apache · Cloudstack

·

CVE-2026-61400

·

Published

2026-08-21

·

Updated

2026-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache CloudStack versions 4.20.0.0 through 4.20.3.0 Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description Command Injection occurs in the run and get diagnostics functionality for system VMs and virtual routers. An authenticated user with necessary permissions can execute arbitrary commands on system VM and Virtual Router instances, running as root or the diagnostics-process user. This can lead to a full compromise of the instance and potentially allow lateral movement within the managed infrastructure, including access to guest network traffic. The affected API endpoints are getDiagnosticsData and runDiagnostics, which are restricted to Admin role accounts by default.
Recommendations Upgrade versions 4.20.0.0 through 4.20.3.0 to 4.20.3.1 or later. Upgrade versions 4.21.0.0 through 4.22.1.0 to 4.22.1.1 or later. Restrict access to the getDiagnosticsData and runDiagnostics API endpoints to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61400

Affected Products

Cloudstack