https://seclists.org/oss-sec/2026/q2/461: CVE-2026-25199: Apache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance Access
Published May 8, 2026
·Updated
Affected Software
1 affected component
Apache CloudStack>=4.21.0.0<=4.22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-25199?
The severity of CVE-2026-25199 is classified as moderate.
2
Which versions of Apache CloudStack are affected by CVE-2026-25199?
CVE-2026-25199 affects Apache CloudStack versions 4.21.0 through 4.22.0.
3
What kind of access does CVE-2026-25199 allow?
CVE-2026-25199 allows unauthorized cross-tenant instance access through the Proxmox extension.
4
How do I fix CVE-2026-25199?
To fix CVE-2026-25199, upgrade to a version of Apache CloudStack that is not affected by this vulnerability.
5
What is the impact of CVE-2026-25199 on cloud security?
The impact of CVE-2026-25199 on cloud security includes a potential breach of tenant isolation and unauthorized data access.