AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-61397

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The OAuth2 authentication plugin and Google OAuth integration in Apache CloudStack versions 4.19.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0 are vulnerable to unauthorized exposure of sensitive information. This vulnerability could allow unauthorized actors to access sensitive data, potentially compromising user privacy and system integrity. Organizations using affected versions should prioritize upgrading to versions 4.20.3.1 or 4.22.1.1 to mitigate this risk.

CVE
CVE-2026-61397
Severity
HIGH
CVSS
7.5
EPSS
0.28%
Apache

Original NVD Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)