Vulnerability Description
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. This vulnerability does not allow them to see the contents of the backup. Users are recommended to upgrade to version 4.22.0.1, which fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cloudstack | >= 4.21.0.0, < 4.22.0.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xmMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/05/09/1Mailing ListThird Party Advisory
FAQ
What is CVE-2025-66170?
CVE-2025-66170 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugi...
How severe is CVE-2025-66170?
CVE-2025-66170 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66170?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cloudstack.