CVE-2025-66171: Apache CloudStack: Any user can create a new VM from backups they should not have access to
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any other user of the environment.
Backup plugin users using CloudStack 4.21.0.0+ are recommended to upgrade to CloudStack version 4.22.0.1, which fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66171?
CVE-2025-66171 has a moderate severity level due to improper access control in the Apache CloudStack Backup plugin.
How do I fix CVE-2025-66171?
To address CVE-2025-66171, you should upgrade the Apache CloudStack Backup plugin to a version that is not affected by this vulnerability.
Who is affected by CVE-2025-66171?
Any user with authenticated access in systems running Apache CloudStack 4.21.0.0 and 4.22.0.0 with the Backup plugin enabled is at risk.
What are the consequences of CVE-2025-66171?
The consequence of CVE-2025-66171 is that unauthorized users can create new virtual machines from backups they should not have access to.
Is there a patch available for CVE-2025-66171?
Yes, upgrading to a patched version of the Apache CloudStack Backup plugin is necessary to mitigate CVE-2025-66171.