CVE-2025-66170: CWE-863: Incorrect Authorization in Apache Software Foundation Apache CloudStack
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.
AI Analysis
Technical Summary
The Apache CloudStack Backup plugin contains an incorrect authorization logic flaw (CWE-863) in versions 4.21.0.0 and 4.22.0.0. This flaw allows any authenticated user with access to certain APIs to enumerate backups across all accounts in the environment. The vulnerability does not expose the contents of the backups, only the ability to list them. The vendor has addressed this issue in version 4.22.0.1.
Potential Impact
Authenticated users can list backups from any account in the affected CloudStack environment, potentially exposing metadata about backups across accounts. However, the contents of the backups remain inaccessible, limiting the impact to information disclosure of backup existence and metadata only.
Mitigation Recommendations
Users should upgrade Apache CloudStack to version 4.22.0.1, which contains the fix for this authorization vulnerability. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the vendor recommendation to upgrade.
CVE-2025-66170: CWE-863: Incorrect Authorization in Apache Software Foundation Apache CloudStack
Description
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.
CVSS v3.1
Score 6.5medium
Affected software
pkg:maven/org.apache.cloudstack/cloudstackRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache CloudStack Backup plugin contains an incorrect authorization logic flaw (CWE-863) in versions 4.21.0.0 and 4.22.0.0. This flaw allows any authenticated user with access to certain APIs to enumerate backups across all accounts in the environment. The vulnerability does not expose the contents of the backups, only the ability to list them. The vendor has addressed this issue in version 4.22.0.1.
Potential Impact
Authenticated users can list backups from any account in the affected CloudStack environment, potentially exposing metadata about backups across accounts. However, the contents of the backups remain inaccessible, limiting the impact to information disclosure of backup existence and metadata only.
Mitigation Recommendations
Users should upgrade Apache CloudStack to version 4.22.0.1, which contains the fix for this authorization vulnerability. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the vendor recommendation to upgrade.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2025-11-22T19:26:03.523Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fddc53cbff5d8610d5567e
Added to database: 05/08/2026, 12:51:31 UTC
Last enriched: 05/08/2026, 13:07:11 UTC
Last updated: 07/31/2026, 19:22:56 UTC
Views: 180
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.