SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-62440

CRITICAL · CVSS 9.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An improper access control vulnerability in the Kubernetes Service plugin of Apache CloudStack allows unauthorized cross-tenant manipulation of the Kubernetes cluster during node management operations. This could lead to significant security risks, including data exposure and service disruption. Organizations using Apache CloudStack versions 4.21.0.0 to 4.22.1.0 should prioritize upgrading to version 4.22.1.1 or later to mitigate this risk.

CVE
CVE-2026-62440
Severity
CRITICAL
CVSS
9.1
EPSS
0.30%
Apache Kubernetes

Original NVD Description

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)