Apache CloudStack Privilege Escalation Vulnerability Allowing Domain Admins to Reset Admin Passwords

Vulnerability

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 prior to 4.20.0.0. In this vulnerability, a malicious Domain Admin user in the ROOT domain can reset the passwords of user accounts with Admin roles. This flaw allows the attacker to take control of higher-privileged accounts, impersonate Admin users, and access sensitive APIs and resources, potentially compromising resource integrity and confidentiality, leading to data loss, denial of service, and availability issues in CloudStack-managed infrastructure.

Impact

Exploitation of this vulnerability allows a Domain Admin to reset Admin passwords, gain control over Admin accounts, and access sensitive APIs and resources, which could result in significant disruptions and data management issues within the CloudStack environment.

Remediation

Users are advised to upgrade to Apache CloudStack versions 4.19.3.0 or 4.20.1.0, both of which address this vulnerability. Instructions for upgrading and downloading these versions are available on the Apache CloudStack website and through the Apache CloudStack download page.

Added: Jun 10, 2025, 11:20 PM
Updated: Jun 10, 2025, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
7.5
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.