CVE-2026-68745: Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures.
Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.20.3.1 - Upgrade
Upgrade
Apache CloudStackto a version that resolves this vulnerability.Fixed in 4.22.1.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Apache CloudStack 4.20.3.0 and 4.22.1.0 are affected on all platforms where SAML authentication is used with an IdP lacking a certificate.
What must an attacker be able to do to exploit this issue?
The attacker must spoof the IdP's IP address or have an attacker-controlled URL registered in the management server. They can then submit a forged SAML response with a forged signature to log on.
Is there a fixed release available?
Yes. Upgrade to Apache CloudStack 4.20.3.1 or 4.22.1.1, or a later version.