AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-59799

HIGH · CVSS 8.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

A vulnerability in Apache CloudStack's Two-factor authentication plugin allows attackers to bypass the two-factor authentication disable flow, potentially compromising user accounts. This affects versions 4.18.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0, making it critical for users of these versions to upgrade to 4.20.3.1 or 4.22.1.1 or later to mitigate the risk. Organizations utilizing affected versions should prioritize this update to enhance their security posture.

CVE
CVE-2026-59799
Severity
HIGH
CVSS
8.8
EPSS
0.30%
Apache

Original NVD Description

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)