AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-59654

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Apache CloudStack is vulnerable due to a missing release of resources after their effective lifetime in its scoped global configuration, impacting various modules and plugins such as Quota and Host-HA. This flaw could lead to a denial of service (DoS) for the management server, potentially disrupting operations. Organizations using affected versions (4.7.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0) should prioritize upgrading to at least version 4.20.3.1 or 4.22.1.1 to mitigate this risk.

CVE
CVE-2026-59654
Severity
HIGH
CVSS
7.5
EPSS
0.23%
Apache

Original NVD Description

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server. This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)