https://seclists.org/oss-sec/2026/q2/457: CVE-2025-66172: Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66172?
CVE-2025-66172 is classified as important.
2
What versions of Apache CloudStack are affected by CVE-2025-66172?
CVE-2025-66172 affects Apache CloudStack versions 4.21.0.0 through 4.22.0.0.
3
What does CVE-2025-66172 exploit in Apache CloudStack?
CVE-2025-66172 exploits improper access logic in the CloudStack Backup plugin.
4
How can I fix CVE-2025-66172?
To mitigate CVE-2025-66172, upgrade to a version of Apache CloudStack that is not affected, beyond 4.22.0.0.
5
Who is affected by CVE-2025-66172?
Any authenticated user in CloudStack 4.21.0.0+ environments could potentially be affected by CVE-2025-66172.