CVE-2026-25077Disclosure(apache / cloudstack)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache cloudstack systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of the KVM-based infrastructure managed by CloudStack. Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudstack

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cloudstack

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 105-0805-0905-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-091
Disclosure1
2026-05-111
Patch1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache CloudStack patches important flaws (CVE-2026-25199, CVE-2026-25077) enabling VM hijacking and KVM host RCE. Secure your cloud environment now. #CloudStack #ApacheCloudStack #CloudSecurity #InfoSec #CyberSecurity #KVM #Proxmox #DevOps https://securityonline.info/apache-cloudstack-security-update-vm-hijacking-kvm-rce-fix/ https://t.co/QrvoCsi0Iv

    Post summary

    Apache CloudStack has released patches for CVE‑2026‑25199 and CVE‑2026‑25077, addressing VM hijacking and KVM host RCE vulnerabilities; users are urged to update immediately.

    1801841.4K
    12.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25077 Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to m… https://www.cve.org/CVERecord?id=CVE-2026-25077

    Post summary

    The entry provides a concise disclosure of CVE‑2026‑25077, outlining a flaw that allows account users to register templates for direct download to primary storage in KVM hypervisors, but does not signal any PoC, exploit, or remediation details.

    00010140
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25077 Arbitrary Code Execution via Unsanitized Template Registration in Apache CloudStack https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25077

    Post summary

    The text announces CVE-2026-25077 as an arbitrary code execution flaw in Apache CloudStack involving unsanitized template registration, but offers no PoC, exploit, or mitigation details.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecloudstack---

Explore more