CVE-2026-50222 | Apache CloudStack up to 4.20.3.0/4.22.1.0 Userdata Reference APIs missing authentication

SecurityVulns

A vulnerability described as very critical has been identified in Apache CloudStack up to 4.20.3.0/4.22.1.0. This vulnerability affects the function deleteUserData/linkUserDataToTemplate/resetUserDataForVirtualMachine/deployVirtualMachine/updateVirtualMachine/deleteCniConfiguration of the component Userdata Reference APIs. The manipulation results in missing authentication.

This vulnerability is identified as CVE-2026-50222. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More