CVE-2026-59657: Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
Published Aug 21, 2026
·Updated
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database.
This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected Software
3 affected components
Apache CloudStack>=4.0.0<=4.20.3.0, >=4.21.0.0<=4.22.1.0
Apache CloudStack>=4.0.0<4.20.3.1
Apache CloudStack>=4.21.0.0<4.22.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Aug 21, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which Apache CloudStack deployments are affected?
Affected versions are 4.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. The issue concerns AsyncJob data stored in the database.
2
What versions remediate the issue?
Upgrade to Apache CloudStack 4.20.3.1, 4.22.1.1, or a later version.