CVE-2026-25199General(apache / cloudstack)

HIGHCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch apache cloudstack systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable instance setting, proxmox_vmid, to associate CloudStack instances with Proxmox virtual machines. Because this value is not restricted or validated against tenant ownership and Proxmox VM IDs are predictable, a non-privileged attacker can modify the setting to reference a VM belonging to another account. This allows unauthorized cross-tenant access and enables full control over the targeted VM, including starting, stopping, and destroying the virtual machine. Users are recommended to upgrade to version 4.22.0.1, which fixes this issue. As a workaround for the existing installations, editing of the proxmox_vmid instance detail by users can be prevented by adding this detail name to the global configuration parameter - user.vm.denied.details.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudstack

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-11)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
cloudstack

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-11: 3PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-11: 1Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 305-0805-0905-11
Signal classification4 categories
General
240.0%
Disclosure
120.0%
Active Exploitation
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-081
General1
2026-05-091
Disclosure1
2026-05-113
Active Exploitation1General1Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache CloudStack patches important flaws (CVE-2026-25199, CVE-2026-25077) enabling VM hijacking and KVM host RCE. Secure your cloud environment now. #CloudStack #ApacheCloudStack #CloudSecurity #InfoSec #CyberSecurity #KVM #Proxmox #DevOps https://securityonline.info/apache-cloudstack-security-update-vm-hijacking-kvm-rce-fix/ https://t.co/QrvoCsi0Iv

    Post summary

    The text announces that Apache CloudStack has released patches for CVE-2026-25199 and CVE-2026-25077, which allow VM hijacking and KVM host RCE, and urges users to update to secure their environments.

    1801841.4K
    12.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-25199 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely lists CVE‑2026‑25199 along with its CVSS score and critical severity, offering no proof‑of‑concept, exploit details, or mitigation information.

    1000037
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/cve-2026-25199-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory highlights CVE‑2026‑25199 as an actively exploited zero‑day, providing PoC and technical details but lacking patch information.

    0000018
    188 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.… https://www.cve.org/CVERecord?id=CVE-2026-25199

    Post summary

    CVE‑2026‑25199 enables tenants to access other tenants’ instances using the Proxmox extension in Apache CloudStack, but no exploit, patch, or PoC details are provided.

    00000181
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25199 Unauthorized Cross-Tenant Access in Apache CloudStack Pro... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25199 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The message merely announces CVE-2026-25199 and links to a vulnerability detail page, without providing any technical specifics, exploit code, patch information, or evidence of active exploitation.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecloudstack---

Explore more