CVE-2026-59657: Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
Published Aug 21, 2026
·Updated
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database.
This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected Software
1 affected component
Apache CloudStack>=4.0.0<=4.20.3.0, >=4.21.0.0<=4.22.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Aug 21, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionWeakness
Frequently Asked Questions
1
Which Apache CloudStack deployments are affected?
Affected versions are 4.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The issue concerns AsyncJob data stored in the database.
2
What versions remediate the issue?
Upgrade to Apache CloudStack 4.20.3.1, 4.22.1.1, or a later version.