VYPR
advisoryPublished Aug 21, 2026· 1 source

Apache CloudStack & InLong: 25 Vulnerabilities Disclosed in Coordinated Batch

Key findings • 25 CVEs disclosed together across Apache CloudStack and InLong in a 21-hour window. • Multiple CloudStack vulnerabilities involve improper access control, authorization, and se…

Key findings

  • 25 CVEs disclosed together across Apache CloudStack and InLong in a 21-hour window.
  • Multiple CloudStack vulnerabilities involve improper access control, authorization, and sensitive information exposure.
  • Command injection and SSRF flaws found in both CloudStack and InLong projects.
  • Apache InLong versions 2.0.0 to 2.4.0 affected by command injection, path traversal, and file access issues.
  • Patches available for CloudStack in versions 4.20.3.1 and 4.22.1.1; InLong users should upgrade to 2.4.0.

On August 20-21, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Apache projects, primarily impacting Apache CloudStack and Apache InLong. The vulnerabilities, disclosed within a 21-hour window, range in severity and affect various functionalities including authentication, authorization, data handling, and command execution. These disclosures highlight potential risks for organizations utilizing these open-source platforms, emphasizing the need for prompt patching and security reviews.

The majority of the disclosed vulnerabilities reside within Apache CloudStack, a powerful Infrastructure as a Service (IaaS) platform. Several CloudStack CVEs relate to improper access control and authorization flaws. CVE-2026-66797, CVE-2026-66722, and CVE-2026-66721 detail issues where unauthorized users or domain administrators could perform actions beyond their intended privileges, affecting annotations, project roles, and host tag listings, respectively. Additionally, CVE-2026-62440 points to cross-tenant manipulation within the Kubernetes Service (CKS) plugin, and CVE-2026-50222 describes missing authorization in Userdata reference APIs.

Several CloudStack vulnerabilities involve the exposure of sensitive information. CVE-2026-65613 and CVE-2026-59085, affecting the Webhook module, could lead to sensitive data exposure or Server-Side Request Forgery (SSRF) during webhook delivery requests. Other information exposure flaws include CVE-2026-61397 and CVE-2026-59655 related to OAuth authentication, CVE-2026-59780 concerning LDAP configurations, and CVE-2026-59657 which details cleartext storage of sensitive information in AsyncJob data. CVE-2026-59654, a Missing Release of Resource after Effective Lifetime vulnerability, could lead to a denial of service.

Command injection and SSRF vulnerabilities are also present in the CloudStack batch. CVE-2026-61400 allows authenticated users to achieve command injection in system VMs and virtual routers via diagnostic functions. CVE-2026-59085 and CVE-2026-50112 highlight SSRF vulnerabilities, with the latter specifically enabling RCE on KVM hypervisors through crafted metalink files. Certificate validation failures in SAML authentication (CVE-2026-68745) present a risk of forged SAML responses. UI-related vulnerabilities like CVE-2026-61399 and CVE-2026-61398 involve improper output encoding, potentially impacting lock user and password reset functionalities.

The Apache InLong project is affected by a set of four vulnerabilities disclosed on August 20, 2026. These include command injection (CVE-2026-63046), relative path traversal (CVE-2026-63043), and two instances of files/directories being accessible to external parties (CVE-2026-63042 and CVE-2026-63040). These flaws in InLong, affecting versions from 2.0.0 before 2.4.0, allow for arbitrary shell command execution, file reads, and logical deletion of stream sources, posing significant security risks.

The vulnerabilities in Apache CloudStack are patched in various versions, including 4.20.3.1 and 4.22.1.1, with specific version recommendations provided for each CVE. For Apache InLong, users are advised to upgrade to version 2.4.0 or apply specific patches. Given the breadth of issues across these Apache projects, users are strongly encouraged to review the specific CVE details and apply the necessary updates to mitigate potential exploitation and ensure the security of their cloud infrastructure and data pipelines. The coordinated disclosure of these vulnerabilities underscores the importance of timely security updates for widely used open-source software.

Synthesized by Vypr AI