Database/Control plane, storage & DevOps
Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to Proxmox
CVSS 9.1CVE-2026-25199Control plane, storage & DevOpscurated
Impact
The extension keys CloudStack instances to Proxmox VMs using a user-editable setting (proxmox_vmid), so a tenant edits that field and gains access to another tenant's instance. A straightforward cross-tenant break in a multi-tenant IaaS control plane.
Who can reach it
Any authenticated CloudStack tenant able to set instance settings.
What to do
Upgrade Apache CloudStack past 4.22.0.0 or disable the Proxmox extension. Until patched, restrict who can edit instance settings - the vulnerable field is user-writable by design.
References
Related entries
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCVE-2026-41475 · BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gatewaysCritical
- Ceph Monitor: any read-only CephX user can dump the config-key store, including cephadm's cluster-wide SSH keyCVE-2026-50152 · Ceph Monitor (MMonSubscribe config-key store authorization)Critical
- Apache Airflow FAB provider: Azure AD id_token issuer and audience unchecked, any tenant can log inCVE-2026-75156 · Apache Airflow FAB provider (Azure AD OAuth id_token issuer/audience validation)Critical
- Airflow Keycloak provider: Keycloak tokens from unsigned cookies are not bound to the session identityCVE-2026-76186 · Apache Airflow Keycloak provider (session identity vs. Keycloak access/refresh token binding)Critical
- Fortra BoKS Manager: command injection in crlserver gives root on the BoKS Master via a crafted CRL URLCVE-2026-79898 · Fortra BoKS Manager crlserver (CRL URL handling)Critical
- Airflow FAB provider: password change through the Admin PATCH endpoint does not evict existing sessionsCVE-2026-86462 · Apache Airflow FAB provider (Admin user-edit PATCH endpoint, session invalidation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.