Cloudstack
Vendor:
First CVE: Oct 26, 2012 · Active for 13 years
45
Total CVEs
More Total CVEs than 97% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloudstack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2012
13 years ago
Most Recent CVE
May 8, 2026
77 days ago
CVE Severity & Scoring
Cloudstack45 CVEs
44%
31%
20%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.2%)
Network35 (77.8%)
Unknown9 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (68.9%)
High5 (11.1%)
Unknown9 (20.0%)
User Interaction
None34 (75.6%)
Unknown9 (20.0%)
Required2 (4.4%)
Privileges Required
Low19 (42.2%)
High4 (8.9%)
None13 (28.9%)
Unknown9 (20.0%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41107HIGH The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiat | Jul 19, 2024 | 8.1 | 46 | NO | YES |
CVE-2026-25199CRITICAL Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.
This issue affects Apache CloudStack: from 4.21.0.0 through 4.22 | May 8, 2026 | 9.1 | 35 | NO | NO |
CVE-2022-35741CRITICAL Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin | Jul 18, 2022 | 9.8 | 35 | NO | NO |
CVE-2012-4501HIGH Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API ca | Oct 26, 2012 | 10.0 | 35 | NO | NO |
CVE-2026-25077HIGH Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file na | May 8, 2026 | 8.8 | 34 | NO | NO |
CVE-2025-66467HIGH Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket wit | May 8, 2026 | 8.1 | 32 | NO | NO |
CVE-2025-66172HIGH The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, whe | May 8, 2026 | 8.1 | 32 | NO | NO |
CVE-2024-38346CRITICAL The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server ho | Jul 5, 2024 | 9.8 | 32 | NO | NO |
CVE-2019-17562CRITICAL A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack o | May 14, 2020 | 9.8 | 32 | NO | NO |
CVE-2016-6813CRITICAL Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of anot | Feb 6, 2018 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Cloudstack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.9.0 | 1 | 9.8 | 5.6% | 0 | 0 |
| 4.8 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.7.0 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.6.2 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.6.1 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.6.0 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.5.2 | 1 | 6.5 | 2.9% | 0 | 0 |
| 4.5.1 | 2 | 5.7 | 2.7% | 0 | 0 |
| 4.4.4 | 1 | 4.9 | 2.5% | 0 | 0 |
| 4.4.1 | 2 | 5.0 | 2.9% | 0 | 0 |
| 4.4.0 | 2 | 5.0 | 2.9% | 0 | 0 |
| 4.3.1 | 1 | 5.0 | 2.6% | 0 | 0 |
| 4.3.0 | 1 | 5.0 | 2.6% | 0 | 0 |
| 4.21.0.0 | 2 | 4.5 | 0.4% | 0 | 0 |
| 4.20.0.0 | 1 | 4.3 | 0.7% | 0 | 0 |
| 4.19.1.0 | 1 | 4.3 | 1.0% | 0 | 0 |
| 4.19.0.0 | 3 | 7.8 | 0.8% | 0 | 0 |
| 4.17.0.0 | 1 | 9.8 | 7.9% | 0 | 0 |
| 4.1.1 | 3 | 3.7 | 2.3% | 0 | 0 |
| 4.1.0 | 3 | 3.7 | 2.3% | 0 | 0 |