CVE-2026-62440
EUVD-2026-6383521.08.2026, 09:16
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | cloudstack | 4.21.0.0 ≤ 𝑥 ≤ 4.22.1.0 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure