CVE-2026-50112Patch(apache / cloudstack)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache cloudstack systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs. RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads: An authenticated CloudStack tenant holding the default User role can execute arbitrary shell commands as root on the KVM hypervisor host that runs other tenants' VMs. This is cross-tenant root on the underlying compute, reachable via the public CloudStack API. When a User registers a VM template with directDownload=true and a URL pointing to a .metalink file, the management server fetches the metalink XML and dispatches download to the KVM agent. Inner URLs inside the metalink XML are never re-validated against the scheme allowlist. These issues affect Apache CloudStack: from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudstack

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cloudstack

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-24: 108-2108-2208-24
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-211
Patch1
2026-08-221
Patch1
2026-08-241
Disclosure1
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-50112 is a critical Apache CloudStack flaw enabling cross-tenant remote code execution as root on KVM hosts. Upgrade to 4.20.3.1 or 4.22.1.1. #ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS http://securityonline.info/cve-2026-50112-cloudstack-rce/

    Post summary

    The post announces a critical RCE flaw in Apache CloudStack (CVE‑2026‑50112) and recommends upgrading to patched releases 4.20.3.1 or 4.22.1.1, while also linking to additional details.

    040112716
    13.0K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-50112:Apache CloudStackの脆弱性により、KVMホスト上でテナント間リモートコード実行が可能になる CVE-2026-50112: Apache CloudStack Flaw Allows Cross-Tenant Remote Code Execution on KVM Hosts #DailyCyberSecurity (Aug 21) https://securityonline.info/cve-2026-50112-cloudstack-rce/

    Post summary

    A new CVE-2026-50112 for Apache CloudStack is disclosed, describing a cross‑tenant remote code execution vulnerability affecting KVM hosts, with no PoC, exploitation, or patch information included.

    00000270
    4.9K followersView on X
  • yousukezan@yousukezan
    Patch

    Apache CloudStackは4.20.3.1と4.22.1.1を公開し、計20件の脆弱性を修正した。最も深刻なCVE-2026-50112では、一般テナントがKVMハイパーバイザー上でroot権限のコード実行に到達できる。 CVE-2026-50112はVMテンプレート処理にあり、UserロールのテナントがdirectDownloadで.metalinkを指定すると、内部URLがスキーム許可リストで再検証されず、KVMエージェント上で任意シェルコマンドをrootとして実行できる。関連してmetalinkのミラー解決を悪用するSSRFも報告された。CVE-2026-47359ではNASバックアップのmountオプション、CVE-2026-61400では診断APIを通じたコマンド実行が可能とされる。修正版は4.20.3.1と4.22.1.1で、記事執筆時点で実際の悪用や公開PoCは確認されていない。 https://securityonline.info/cve-2026-50112-cloudstack-rce/

    Post summary

    Apache CloudStack issued patches for 20 vulnerabilities, notably CVE‑2026‑50112 which allows root code execution through metalink processing, but no PoC or real-world exploitation has yet been reported.

    00000991
    14.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecloudstack---

Explore more