CVE-2026-66797
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026
Descripción
*** Pendiente de traducción *** Improper access control in CloudStack&#39;s annotation functionality allows unauthorized comment creation and disclosure.<br />
<br />
<br />
<br />
<br />
The addAnnotation and listAnnotation APIs perform an ownership check when an entity&#39;s UUID is specified, but fail to honor its result correctly. This lets any authenticated user write annotations to, and disclose existing annotations/comments on, an entity they don&#39;t own by simply supplying its UUID.<br />
<br />
<br />
<br />
<br />
This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.<br />
<br />
<br />
<br />
<br />
<br />
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Impacto
Puntuación base 3.x
5.40
Gravedad 3.x
MEDIA


