https://seclists.org/oss-sec/2026/q2/455: CVE-2025-66170: Apache CloudStack: Any user can list backups that they should not have access to
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66170?
The severity of CVE-2025-66170 is classified as low.
2
Which versions of Apache CloudStack are affected by CVE-2025-66170?
CVE-2025-66170 affects Apache CloudStack versions 4.21.0.0 through 4.22.0.0.
3
What does CVE-2025-66170 exploit in Apache CloudStack?
CVE-2025-66170 exploits improper authorization logic in the CloudStack Backup plugin.
4
Who is impacted by CVE-2025-66170?
Any authenticated user with access to CloudStack 4.21.0.0+ environments is impacted by CVE-2025-66170.
5
How can I resolve the issues related to CVE-2025-66170?
To resolve CVE-2025-66170, it is recommended to upgrade to a version of Apache CloudStack that is not affected by this vulnerability.