Database/Control plane, storage & DevOps

Apache CloudStack: metalink template registration gives a tenant root on the KVM hypervisor host
Impact
A tenant holding only the default User role can execute shell commands as root on the KVM host that runs other tenants' VMs. Registering a template with directDownload=true and a .metalink URL makes the management server fetch the metalink XML and hand the download to the KVM agent, and the inner URLs inside that XML are never re-checked against the scheme allowlist. The same path also gives server-side request forgery through the Secondary Storage VM, which retrieves internal targets and persists them as a template that can then be downloaded through normal APIs. This is cross-tenant root on shared compute reached through the public CloudStack API, so on a GPU cloud built on CloudStack it puts one tenant on the hypervisor underneath everyone else's accelerators.
Who can reach it
Any authenticated CloudStack account with the default User role, over the public API. No admin privilege, no operator interaction, no access to the management network required.
What to do
Upgrade to 4.20.3.1 or 4.22.1.1 or later; versions 4.14.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. That means updating the management servers and the KVM agents and restarting those daemons - agent restarts are live-migration friendly but should still be staged per host. Until then, treat direct-download template registration as a privileged operation and restrict which accounts may register templates from URLs.
References
Related entries
- Jenkins: attacker-controlled config.xml deserialization allows user impersonation and code executionCVE-2026-53435 · Jenkins controller (config.xml deserialization of arbitrary core and plugin types)High
- Apache Airflow: executor_config deserialization imports arbitrary callables in scheduler and API serverCVE-2026-58076 · Apache Airflow serialization layer (exception branch reached via operator executor_config)High
- rclone (serve restic --private-repos): --private-repos is meant to confine each authenticated user to their ownCVE-2026-59733 · rclone (serve restic --private-repos)High
- Red Hat ACM: ManagedClusterAddOn annotation overrides governance-policy image, giving cluster-admin execCVE-2026-66793 · Red Hat Advanced Cluster Management governance-policy-addon-controllerHigh
- Apache Airflow: Callback deserialization in the scheduler timeout sweep imports Dag-author-chosen modulesCVE-2026-67587 · Apache Airflow Task SDK Callback deserialization (task instance next_kwargs)High
- Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): A VXLAN tunnel's `changelink()` operates acrossCVE-2026-68432 · Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.