PatchSiren

Apache Software Foundation CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Apache Software Foundation CVE published 2026-09-10

CVE-2026-80351

CVE-2026-80351 is an improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. Tenant-controlled repository content can influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. Affected versions are Apache Camel K from 2.0.0 before 2.9.3 and from 2.10.1 before [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-10

CVE-2026-67593

CVE-2026-67593 is a critical vulnerability in Apache Artemis, allowing remote attackers to delete queues on the broker before or after authentication and authorization. This issue affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

CRITICAL Apache Software Foundation CVE published 2026-09-10

CVE-2026-57967

CVE-2026-57967 debrief based on the supplied source corpus. The vulnerability affects Apache Artemis and Apache ActiveMQ Artemis, allowing unauthenticated remote attackers to steal existing sessions and assume ongoing execution of previously authenticated sessions. Defenders should assess exposure and prioritize upgrading to version 2.57.0. The issue is caused by a flaw in the CORE protocol SESSION_REATTA [truncated]

HIGH Apache Software Foundation CVE published 2026-09-10

CVE-2026-49363

CVE-2026-49363 is a HIGH severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. The issue affects Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which [truncated]

HIGH Apache Software Foundation CVE published 2026-09-09

CVE-2026-74761

CVE-2026-74761 Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms allows an authenticated client to spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19 [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-08

CVE-2026-75156

CVE-2026-75156 debrief: Apache Airflow FAB provider vulnerable to unauthorized authentication via Azure AD OAuth. The vulnerability allows attackers to authenticate to Airflow UI with no prior access by registering an Azure tenant and minting an id_token. Affected deployments are those with Azure AD configured as an OAuth provider. The fix involves upgrading to apache-airflow-providers-fab 3.8.1 or later. [truncated]

Review Apache Software Foundation CVE published 2026-09-07

CVE-2026-78254

CVE-2026-78254 Apache Ant FTP and SCP Task Path Traversal. Apache Ant versions prior to 1.10.18 have a vulnerability in the ftp and scp tasks that allows a malicious server to write outside of the dedicated target directory for downloads. This could lead to potential path traversal and file overwrite. Defenders responsible for Apache Ant deployments should assess exposure and upgrade to version 1.10.18 or [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-02

CVE-2026-32773

The CVE-2026-32773 record indicates a lack of XSS escaping in the Spark History Server prior to 3.5.8. This vulnerability allows a malicious Spark job to generate arbitrary unescaped frontend code, potentially leading to minimal privilege escalation in the browser. The exploit requires both high permissions to launch a Spark job and social engineering to trick a user with higher permissions into visiting [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-31

CVE-2026-76984

The CVE-2026-76984 vulnerability is caused by improper neutralization of input during web page generation in Apache Wicket. Specifically, the org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags, but only escaped attribute names, not attribute values. This allows an attacker to influence attribute values and potentially inject malicious code. The issue affects multiple [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-31

CVE-2026-76983

The CVE-2026-76983 vulnerability affects Apache Wicket, a popular Java web application framework. The vulnerability is caused by improper neutralization of input during web page generation, specifically in the <wicket:label> tag. This allows an attacker to inject malicious markup, potentially leading to security issues. Apache Wicket users, developers, and administrators should be aware of this vulnerabil [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-31

CVE-2026-76982

The CVE-2026-76982 vulnerability affects Apache Wicket, a popular Java web application framework. The vulnerability is caused by improper neutralization of input during web page generation, which can lead to cross-site scripting (XSS) attacks. The issue occurs when a Button is rendered on a <button> element and its model holds data an attacker can influence. Apache Wicket users, developers, and administra [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-31

CVE-2026-75802

The Apache Wicket project has addressed a medium-severity vulnerability in several AjaxEditable components. CVE-2026-75802 describes an issue where user-influenced data can be injected as HTML or script into the rendered label of certain Wicket components, affecting users viewing the page. The vulnerability exists when using a non-null IChoiceRenderer with AjaxEditableChoiceLabel or when overriding the de [truncated]

Review Apache Software Foundation CVE published 2026-08-31

CVE-2026-71378

The CVE-2026-71378 vulnerability affects Apache Wicket versions 9.1.0 through 9.23.0 and 10.0.0 through 10.10.0. It is a cross-site request forgery vulnerability due to the default policy of FetchMetadataResourceIsolationPolicy allowing unsafe requests. The vulnerability allows attackers to run listeners inside an authenticated session, potentially leading to cross-site request forgery attacks. Users are [truncated]

HIGH Apache Software Foundation CVE published 2026-08-27

CVE-2026-75020

The CVE-2026-75020 vulnerability is an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') issue in Apache APISIX. A caller with valid credentials for one LDAP directory entry can authenticate as a consumer mapped to a different entry, bypassing the plugin's configured scope. This issue affects Apache APISIX versions from 2.11.0 through 3.17.0. The vulnerability can be add [truncated]

HIGH Apache Software Foundation CVE published 2026-08-27

CVE-2026-74848

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T10:16:36.337Z and has not been modified since then. CVE-2026-74848 is an Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin rou [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-25

CVE-2026-55976

A Server-Side Request Forgery (SSRF) vulnerability exists in Apache Hive before version 4.2.1. An authenticated remote attacker with CREATE TABLE privilege can cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on an Avro table that is subsequently queried. This can expose cloud instance metadata, internal network services, or local server files to [truncated]

HIGH Apache Software Foundation CVE published 2026-08-25

CVE-2026-53561

CVE-2026-53561 is an improper authentication vulnerability in Apache Hive 4.0.0 through 4.2.0 with SAML bearer-token validation enabled, allowing unauthenticated network attackers to authenticate as arbitrary Hive users via forged Authorization: Bearer tokens sent to the /cliservice HTTP endpoint. This issue requires network reachability to the HiveServer2 HTTP port, directly or through a reverse proxy li [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-25

CVE-2026-49845

CVE-2026-49845 is a SQL injection issue in Apache Hive that allows authenticated users to read, modify, or affect partition metadata via crafted partition names in metastore RPC requests when direct SQL is enabled. The issue is fixed in version 4.2.1. Defenders of Apache Hive deployments should assess exposure and prioritize upgrading to version 4.2.1 or later. The vulnerability impacts partition metadata [truncated]

HIGH Apache Software Foundation CVE published 2026-08-25

CVE-2026-49050

A general user can mint admin access tokens via /access-tokens in Apache DolphinScheduler before 3.4.2. This vulnerability allows unauthorized access and potential privilege elevation. Users are recommended to upgrade to version 3.4.2. The issue affects Apache DolphinScheduler, specifically versions before 3.4.2, and has a high CVSS score of 8.8, indicating a severe security risk. Administrators and users [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-21

CVE-2026-59654

CVE-2026-59654 is a Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. This issue affects various modules and plugins, potentially leading to a denial of service (DoS) scenario for the management server. The vulnerability exists in versions from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users should review t [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-21

CVE-2026-66797

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:40.577Z and has not been modified since then. Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its [truncated]

Review Apache Software Foundation CVE published 2026-08-21

CVE-2026-66722

CVE-2026-66722 is a critical vulnerability affecting Apache CloudStack, specifically impacting project role permissions for domain admins. The issue allows malicious Domain Admins to tamper with project roles and permissions across unrelated domains. This vulnerability affects Apache CloudStack versions 4.15.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Domain admins and security teams should review [truncated]

Review Apache Software Foundation CVE published 2026-08-21

CVE-2026-66721

Apache CloudStack has a missing authorization issue for domain admins in its host tags listing functionality. By default, domain admins can call the listHostTags API, but it returns host tags for all hosts in the environment without domain scoping. This should be restricted to hosts dedicated to that admin's domain. The issue affects Apache CloudStack versions from 4.12.0.0 through 4.20.3.0 and from 4.21. [truncated]

Review Apache Software Foundation CVE published 2026-08-21

CVE-2026-62440

The CVE-2026-62440 record describes an Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack versions from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later. The vulnerability has significant securi [truncated]

Review Apache Software Foundation CVE published 2026-08-21

CVE-2026-61422

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicious template or ISO registration risk, as URL validation st [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-61400

CVE-2026-61400 is an Improper Neutralization of Special Elements used in a Command vulnerability in Apache CloudStack's run and get diagnostics functionality. An authenticated user with specific permissions can execute arbitrary commands as root on system VMs and Virtual Routers. This vulnerability affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The CV [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-21

CVE-2026-61399

Apache CloudStack's UI has an Improper Encoding or Escaping of Output vulnerability when using the Lock User Functionality. This issue affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The vulnerability has a medium priority due to limited scope. Users should upgrade to version 4.20.3.1 or 4.22.1.1 or later. Operators, platform administrators, and securi [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-21

CVE-2026-61398

The Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI, specifically in the Instance Reset Password functionality, affects versions from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. This issue can have a significant operational impact, as it may allow attackers to manipulate output, potentially leading to security breaches. Users are advised to upgrade to vers [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-61397

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue. The vulnerability allows unauthorized actors to access sens [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-59799

The CVE-2026-59799 record describes an Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin, allowing bypass of the two-factor authentication disable flow. The issue affects Apache CloudStack versions from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the is [truncated]