PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50112 Apache Software Foundation CVE debrief

CVE-2026-50112 involves SSRF and RCE vulnerabilities in Apache CloudStack, allowing an authenticated tenant to register a template pointing to an attacker-controlled metalink file, potentially leading to cross-tenant root access on the KVM hypervisor host. Affected versions include Apache CloudStack from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later. Evidence is limited; primary official records indicate these versions are affected. Additional verification is required to confirm affected scope and assess potential impact on specific deployments.

Vendor
Apache Software Foundation
Product
Apache CloudStack
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Apache CloudStack users, administrators, and security teams should be aware of this vulnerability and take necessary actions to upgrade and protect their environments. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Additionally, operators and platform administrators should assess potential impact on specific deployments and prioritize upgrading to version 4.20.3.1 or 4.22.1.1 or later. Vulnerability management teams should incorporate this information into their risk assessments and mitigation strategies. Asset inventory management should be reviewed to identify potentially affected systems. Rollback/change windows should be planned for upgrades. Source tracking should be implemented to monitor for potential exploitation attempts. Monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts. Compensating controls should be implemented for exposed systems while remediation is scheduled and verified. Exposure review should be conducted to assess potential impact on specific deployments. Vendor patch guidance should be followed for upgrades. Asset owners should be notified and involved in the remediation process. Security teams should review and adjust their incident response plans accordingly. The vulnerability management process should be updated to include this information. The security awareness program should be updated to include information about this vulnerability and the necessary actions to take. The incident response plan should be updated to include procedures for handling potential exploitation attempts. The vulnerability should be added to the organization's vulnerability management program. The organization's security policies and procedures should be reviewed and updated as necessary. The security team should provide guidance on how to implement compensating controls for exposed systems. The security team should be

Technical summary

CVE-2026-50112 involves SSRF and RCE vulnerabilities in Apache CloudStack. An authenticated tenant can register a template pointing to an attacker-controlled metalink file, potentially leading to cross-tenant root access on the KVM hypervisor host. The vulnerability affects Apache CloudStack versions from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users should review and restrict access to the public CloudStack API.

Defensive priority

Apache CloudStack users should prioritize upgrading to version 4.20.3.1 or 4.22.1.1 to address potential SSRF and RCE vulnerabilities.

Recommended defensive actions

  • Upgrade Apache CloudStack to version 4.20.3.1 or 4.22.1.1 or later
  • Review and restrict access to the public CloudStack API
  • Monitor for suspicious template registrations and downloads
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence is limited; primary official records indicate Apache CloudStack versions from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0 are affected. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later. Additional verification is required to confirm affected scope and to assess potential impact on specific deployments.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:38.150Z and has not been modified since then.