AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-59780

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The LDAP authentication plugin in Apache CloudStack is vulnerable, allowing any authenticated user to list sensitive LDAP configurations via the listLdapConfigurations API, which is accessible by default to all roles. This exposure could lead to unauthorized access to sensitive information, potentially compromising the security of the system. Organizations using affected versions (4.2.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0) should prioritize upgrading to versions 4.20.3.1 or 4.22.1.1 or later to mitigate this risk.

CVE
CVE-2026-59780
Severity
HIGH
CVSS
7.5
EPSS
0.28%
Apache

Original NVD Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles. This issue affects Apache CloudStack: from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)