Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-66797

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-284 Control de acceso incorrecto
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026

Descripción

*** Pendiente de traducción *** Improper access control in CloudStack&amp;#39;s annotation functionality allows unauthorized comment creation and disclosure.<br /> <br /> <br /> <br /> <br /> The addAnnotation and listAnnotation APIs perform an ownership check when an entity&amp;#39;s UUID is specified, but fail to honor its result correctly. This lets any authenticated user write annotations to, and disclose existing annotations/comments on, an entity they don&amp;#39;t own by simply supplying its UUID.<br /> <br /> <br /> <br /> <br /> This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.<br /> <br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Referencias a soluciones, herramientas e información