CVE-2026-47359Patch(apache / cloudstack)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache cloudstack systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0) accept unsanitized command options for the backup repository. A malicious operator account can exploit this to inject arbitrary commands that execute on the KVM hypervisor host when any account subsequently performs a backup restore. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudstack

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
cloudstack

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-23: 2Patch / Workaround · 2026-08-23: 2Technical Details · 2026-08-23: 208-23
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Patch

    Apache CloudStack acaba de parchear una vulnerabilidad de inyección de comandos (CVE-2026-47359) que permite a una cuenta de operador malicioso ejecutar código arbitrario en hosts hipervisores KVM. La falla reside en

    Post summary

    Apache CloudStack has released a patch for CVE‑2026‑47359, a command‑injection flaw that could let an operator run arbitrary code on KVM hypervisors.

    10000112
    22.5K followersView on X
  • Ciberseguridad LATAM@CibersegLATAM
    Patch

    Apache CloudStack acaba de parchear una vulnerabilidad de inyección de comandos (CVE-2026-47359) que permite a una

    Post summary

    Apache CloudStack has released a patch for the command injection vulnerability CVE‑2026‑47359. No evidence of active exploitation or exploit code is mentioned.

    1000096
    22.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecloudstack---

Explore more