Skip to content
cyberMEDIUM2026-05-08 12:06 UTC

CVE-2025-66170 - Apache CloudStack: Any user can list backups that they should not have access to

CVE ID :CVE-2025-66170 Published : May 8, 2026, 12:06 p.m. | 57 minutes ago Description :The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber