Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cloudstack |
|
| Vendors & Products |
Apache
Apache cloudstack |
Fri, 21 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue. | |
| Title | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP | |
| Weaknesses | CWE-347 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-21T08:21:29.200Z
Reserved: 2026-07-31T12:59:36.386Z
Link: CVE-2026-68745
No data.
Status : Received
Published: 2026-08-21T09:16:40.697
Modified: 2026-08-21T09:16:40.697
Link: CVE-2026-68745
No data.
OpenCVE Enrichment
Updated: 2026-08-21T10:15:13Z