SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-59655

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The OAuth authentication plugin in Apache CloudStack versions 4.19.0.0 to 4.22.1.0 is vulnerable to unauthorized exposure of sensitive information when listing OAuth providers. This could allow attackers to gain access to confidential data, potentially compromising user privacy and security. Organizations using affected versions should prioritize upgrading to at least 4.20.3.1 or 4.22.1.1 to mitigate this risk.

CVE
CVE-2026-59655
Severity
HIGH
CVSS
7.5
EPSS
0.34%
Apache

Original NVD Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)