AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-61398

CRITICAL · CVSS 9.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Apache CloudStack versions 4.15.1.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0 are vulnerable due to improper encoding or escaping of output in the UI's Instance Reset Password functionality. This flaw could potentially allow an attacker to execute cross-site scripting (XSS) attacks, compromising user data and system integrity. Organizations using affected versions should prioritize upgrading to 4.20.3.1 or 4.22.1.1 or later to mitigate this risk.

CVE
CVE-2026-61398
Severity
CRITICAL
CVSS
9.1
EPSS
0.24%
Apache

Original NVD Description

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)