CVE-2026-61400 | Apache CloudStack up to 4.20.3.0/4.22.1.0 Diagnostics getDiagnosticsData/runDiagnostics command injection

SecurityVulns

A vulnerability classified as very critical has been found in Apache CloudStack up to 4.20.3.0/4.22.1.0. This issue affects the function getDiagnosticsData/runDiagnostics of the component Diagnostics. This manipulation causes command injection.

This vulnerability is tracked as CVE-2026-61400. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More