CVE-2026-61399: Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality.
This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Frequently Asked Questions
Which CloudStack releases need to be remediated?
The affected release ranges are 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Upgrade to 4.20.3.1, 4.22.1.1, or a later version.
Is the issue limited to a particular CloudStack UI workflow?
Yes. The vulnerability is in the UI's Lock User functionality, where output is improperly encoded or escaped.