AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-61399

MEDIUM · CVSS 4.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

A vulnerability in Apache CloudStack's UI related to improper encoding or escaping of output affects versions 4.20.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0, specifically when using the Lock User functionality. This flaw could potentially lead to security issues, such as injection attacks, compromising the integrity of the application. Organizations utilizing affected versions should prioritize upgrading to 4.20.3.1 or 4.22.1.1 or later to mitigate the risk.

CVE
CVE-2026-61399
Severity
MEDIUM
CVSS
4.8
EPSS
0.14%
Apache

Original NVD Description

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)