CVE-2026-25077: Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of the KVM-based infrastructure managed by CloudStack.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25077?
CVE-2026-25077 is rated as high severity due to its potential for unauthenticated command injection.
How do I fix CVE-2026-25077?
To mitigate CVE-2026-25077, upgrade Apache CloudStack to version 4.22.0.2 or later where the vulnerability has been addressed.
Who is affected by CVE-2026-25077?
Apache CloudStack users running versions up to 4.20.3.0 and 4.22.0.1 are vulnerable to CVE-2026-25077.
What does CVE-2026-25077 allow an attacker to do?
CVE-2026-25077 allows attackers to perform unauthenticated command injection by exploiting missing file name sanitization.
When was CVE-2026-25077 disclosed?
CVE-2026-25077 was disclosed on a mailing list by Apache, although the exact date of disclosure isn't specified.