Home

Description

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.

PUBLISHED Reserved 2025-11-22 | Published 2026-05-08 | Updated 2026-05-08 | Assigner apache

Problem types

CWE-863: Incorrect Authorization

Product status

Default status
unaffected

4.21.0.0 (custom)
affected

Credits

Gabriel Ortiga Fernandes <gabriel.ortiga@hotmail.com> reporter

Fabricio Duarte <fabricio.duarte.jr@gmail.com> reporter

Gabriel Pordeus Santos <gabrielpordeus@gmail.com> reporter

References

lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xm vendor-advisory

cve.org (CVE-2025-66170)

nvd.nist.gov (CVE-2025-66170)

Download JSON