CVE-2026-62440 PUBLISHED

Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation

Assigner: apache
Reserved: 14.07.2026 Published: 21.08.2026 Updated: 21.08.2026

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.

This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache CloudStack
Versions Default: unaffected
  • affected from 4.21.0.0 to 4.22.1.0 (incl.)

Credits

  • George Chen (GitHub: geo-chen) reporter
  • D0HY30N (GitHub: D0HY30N) reporter

References

Problem Types

  • CWE-284 Improper Access Control CWE