LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-68745

apache · cloudstack

Published
CVSS8.1
Severityhigh
WeaknessCWE-347
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-68745

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-68745.