https://seclists.org/oss-sec/2026/q2/458: CVE-2025-66467: Apache CloudStack: MinIO policy mains intact on bucket deletion
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.19.0.0<=4.20.2.0, >=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66467?
The severity of CVE-2025-66467 is classified as important.
2
Which versions of Apache CloudStack are affected by CVE-2025-66467?
CVE-2025-66467 affects Apache CloudStack versions 4.19.0.0 through 4.20.2.0 and 4.21.0.0 through 4.22.0.0.
3
What is the main issue described in CVE-2025-66467?
The main issue in CVE-2025-66467 is the missing MinIO policy cleanup on bucket deletion, which allows users to retain access to previously owned buckets.
4
How do I mitigate CVE-2025-66467 in my Apache CloudStack deployment?
To mitigate CVE-2025-66467, ensure that you upgrade to a version of Apache CloudStack that addresses this vulnerability.
5
What are the potential risks associated with CVE-2025-66467?
The potential risks of CVE-2025-66467 include unauthorized access to sensitive data in buckets after ownership transfer.