PatchSiren cyber security CVE debrief
CVE-2026-47359 Apache Software Foundation CVE debrief
The CVE-2026-47359 record describes an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API and updateBackupRepository API accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. The CVE record was published on 2026-08-21T09:16:38.000Z and has not been modified since then. Limited evidence is available, and further verification is recommended.
- Vendor
- Apache Software Foundation
- Product
- Apache CloudStack
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-27
Who should care
Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. This includes reviewing system configurations, monitoring for suspicious activity, and planning for vendor-supported updates or mitigations.
Technical summary
The addBackupRepository API and updateBackupRepository API in Apache CloudStack's NAS backup provider plugin accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.
Defensive priority
Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.
Recommended defensive actions
- Upgrade to version 4.20.3.1 or 4.22.1.1 or later
- Review and update backup repository configurations
- Monitor for suspicious activity on KVM hypervisor hosts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin, affecting versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Limited evidence is available, and further verification is recommended. Evidence limits suggest verifying the vulnerability through official channels and reviewing system configurations for potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47359 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47359
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47359 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47359
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.