CVE-2026-66797 | Apache CloudStack up to 4.20.3.0/4.22.1.0 Annotation addAnnotation/listAnnotation uuid access control
A vulnerability, which was classified as critical, has been found in Apache CloudStack up to 4.20.3.0/4.22.1.0. The affected element is the function addAnnotation/listAnnotation of the component Annotation. Performing a manipulation of the argument uuid results in improper access controls.
This vulnerability is cataloged as CVE-2026-66797. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More