https://seclists.org/oss-sec/2026/q2/456: CVE-2025-66171: Apache CloudStack: Any user can cate a new VM from backups they should not have access to
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66171?
The severity of CVE-2025-66171 is classified as important.
2
Which versions of Apache CloudStack are affected by CVE-2025-66171?
CVE-2025-66171 affects Apache CloudStack versions 4.21.0.0 through 4.22.0.0.
3
What is the primary issue caused by CVE-2025-66171?
CVE-2025-66171 allows any authenticated user to create a new VM from backups that they should not have access to.
4
How do I fix CVE-2025-66171?
To fix CVE-2025-66171, users should upgrade to a version of Apache CloudStack that is not affected, specifically newer than 4.22.0.0.
5
Who is at risk from CVE-2025-66171?
Any authenticated users in Apache CloudStack environments using the affected versions are at risk due to improper access control.