PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47359 Apache Software Foundation CVE debrief

The CVE-2026-47359 record describes an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API and updateBackupRepository API accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. The CVE record was published on 2026-08-21T09:16:38.000Z and has not been modified since then. Limited evidence is available, and further verification is recommended.

Vendor
Apache Software Foundation
Product
Apache CloudStack
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Operators and administrators of Apache CloudStack, particularly those with KVM hypervisor hosts, should be aware of this vulnerability and take steps to upgrade and monitor their systems. This includes reviewing system configurations, monitoring for suspicious activity, and planning for vendor-supported updates or mitigations.

Technical summary

The addBackupRepository API and updateBackupRepository API in Apache CloudStack's NAS backup provider plugin accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.

Defensive priority

Operators of Apache CloudStack should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later to address the OS command injection vulnerability.

Recommended defensive actions

  • Upgrade to version 4.20.3.1 or 4.22.1.1 or later
  • Review and update backup repository configurations
  • Monitor for suspicious activity on KVM hypervisor hosts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record indicates an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin, affecting versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Limited evidence is available, and further verification is recommended. Evidence limits suggest verifying the vulnerability through official channels and reviewing system configurations for potential exposure.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:38.000Z and has not been modified since then.