Database/Control plane, storage & DevOps
Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to Proxmox
CVE-2026-25199Control plane, storage & DevOpscurated
Impact
The extension keys CloudStack instances to Proxmox VMs using a user-editable setting (proxmox_vmid), so a tenant edits that field and gains access to another tenant's instance. A straightforward cross-tenant break in a multi-tenant IaaS control plane.
Who can reach it
Any authenticated CloudStack tenant able to set instance settings.
What to do
Upgrade Apache CloudStack past 4.22.0.0 or disable the Proxmox extension. Until patched, restrict who can edit instance settings - the vulnerable field is user-writable by design.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.