CVE-2026-62440
N/A
N/A
Summary
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.
This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CloudStack | 4.21.0.0 <= 4.22.1.0 | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.