PatchSiren cyber security CVE debrief
CVE-2026-50112 Apache Software Foundation CVE debrief
CVE-2026-50112 involves SSRF and RCE vulnerabilities in Apache CloudStack, allowing an authenticated tenant to register a template pointing to an attacker-controlled metalink file, potentially leading to cross-tenant root access on the KVM hypervisor host. Affected versions include Apache CloudStack from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later. Evidence is limited; primary official records indicate these versions are affected. Additional verification is required to confirm affected scope and assess potential impact on specific deployments.
- Vendor
- Apache Software Foundation
- Product
- Apache CloudStack
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-27
Who should care
Apache CloudStack users, administrators, and security teams should be aware of this vulnerability and take necessary actions to upgrade and protect their environments. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Additionally, operators and platform administrators should assess potential impact on specific deployments and prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later. Vulnerability management teams should incorporate this information into their risk assessments and mitigation strategies. Asset inventory management should be reviewed to identify potentially affected systems. Rollback/change windows should be planned for upgrades. Source tracking should be implemented to monitor for potential exploitation attempts. Monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts. Compensating controls should be implemented for exposed systems while remediation is scheduled and verified. Exposure review should be conducted to assess potential impact on specific deployments. Vendor patch guidance should be followed for upgrades. Asset owners should be notified and involved in the remediation process. Security teams should review and adjust their incident response plans accordingly. The vulnerability management process should be updated to include this information. The security awareness program should be updated to include information about this vulnerability and the necessary actions to take. The incident response plan should be updated to include procedures for handling potential exploitation attempts. The vulnerability should be added to the organization's vulnerability management program. The organization's security policies and procedures should be reviewed and updated as necessary. The security team should provide guidance on how to implement compensating controls for exposed systems. The security team should be
Technical summary
CVE-2026-50112 involves SSRF and RCE vulnerabilities in Apache CloudStack. An authenticated tenant can register a template pointing to an attacker-controlled metalink file, potentially leading to cross-tenant root access on the KVM hypervisor host. The vulnerability affects Apache CloudStack versions from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users should review and restrict access to the public CloudStack API.
Defensive priority
Apache CloudStack users should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 to address potential SSRF and RCE vulnerabilities.
Recommended defensive actions
- Upgrade Apache CloudStack to version 4.20.3.1 or 4.22.1.1 or later
- Review and restrict access to the public CloudStack API
- Monitor for suspicious template registrations and downloads
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence is limited; primary official records indicate Apache CloudStack versions from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0 are affected. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later. Additional verification is required to confirm affected scope and to assess potential impact on specific deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50112 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50112
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50112 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50112
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.