CVE-2026-59799: Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable Flow
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow.
This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Frequently Asked Questions
Which CloudStack deployments need remediation?
Deployments running Apache CloudStack 4.18.0.0 through 4.20.3.0, or 4.21.0.0 through 4.22.1.0, are affected if they use the Two-factor authentication plugin.
What must an attacker be able to do to exploit this issue?
The provided information identifies a missing privilege check in the Two-factor authentication plugin's disable flow, allowing that flow to be bypassed. It does not specify the access level, credentials, or network position required.
What fixed versions are available?
Upgrade to Apache CloudStack 4.20.3.1 or 4.22.1.1, or a later version. These versions fix the issue.