This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apache Cloudstack |
|
| Vendors & Products |
Apache
Apache apache Cloudstack |
Fri, 21 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue. | |
| Title | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-21T08:23:55.427Z
Reserved: 2026-07-14T14:34:44.941Z
Link: CVE-2026-62440
No data.
Status : Received
Published: 2026-08-21T09:16:39.963
Modified: 2026-08-21T09:16:39.963
Link: CVE-2026-62440
No data.
OpenCVE Enrichment
Updated: 2026-08-21T11:15:03Z