CVE-2026-50222 | Apache CloudStack up to 4.20.3.0/4.22.1.0 Userdata Reference APIs missing authentication
A vulnerability described as very critical has been identified in Apache CloudStack up to 4.20.3.0/4.22.1.0. This vulnerability affects the function deleteUserData/linkUserDataToTemplate/resetUserDataForVirtualMachine/deployVirtualMachine/updateVirtualMachine/deleteCniConfiguration of the component Userdata Reference APIs. The manipulation results in missing authentication.
This vulnerability is identified as CVE-2026-50222. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More