GPU VulnDB

Database/Control plane, storage & DevOps

Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to Proxmox

CVE-2026-25199Control plane, storage & DevOpscurated

Impact

The extension keys CloudStack instances to Proxmox VMs using a user-editable setting (proxmox_vmid), so a tenant edits that field and gains access to another tenant's instance. A straightforward cross-tenant break in a multi-tenant IaaS control plane.

Who can reach it

Any authenticated CloudStack tenant able to set instance settings.

What to do

Upgrade Apache CloudStack past 4.22.0.0 or disable the Proxmox extension. Until patched, restrict who can edit instance settings - the vulnerable field is user-writable by design.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.