PatchSiren cyber security CVE debrief
CVE-2026-47359 Apache Software Foundation CVE debrief
The CVE-2026-47359 record describes an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API and updateBackupRepository API accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. The CVE record was published on 2026-08-21T09:16:38.000Z and has not been modified since then. Limited evidence is available, and further verification is recommended.
- Vendor
- Apache Software Foundation
- Product
- Apache CloudStack
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. This includes reviewing system configurations, monitoring for suspicious activity, and planning for vendor-supported updates or mitigations.
Technical summary
The addBackupRepository API and updateBackupRepository API in Apache CloudStack's NAS backup provider plugin accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.
Defensive priority
Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.
Recommended defensive actions
- Upgrade to version 4.20.3.1 or 4.22.1.1 or later
- Review and update backup repository configurations
- Monitor for suspicious activity on KVM hypervisor hosts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin, affecting versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Limited evidence is available, and further verification is recommended. Evidence limits suggest verifying the vulnerability through official channels and reviewing system configurations for potential exposure.
Official resources
-
CVE-2026-47359 CVE record
CVE.org
-
CVE-2026-47359 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:38.000Z and has not been modified since then.