Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.
This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apache Cloudstack |
|
| Vendors & Products |
Apache
Apache apache Cloudstack |
Fri, 21 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue. | |
| Title | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulation | |
| Weaknesses | CWE-284 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-21T08:23:55.427Z
Reserved: 2026-07-14T14:34:44.941Z
Link: CVE-2026-62440
No data.
Status : Received
Published: 2026-08-21T09:16:39.963
Modified: 2026-08-21T09:16:39.963
Link: CVE-2026-62440
No data.
OpenCVE Enrichment
Updated: 2026-08-21T11:15:03Z
Weaknesses