CVE-2026-25077 | Apache CloudStack up to 4.20.2.0/4.22.0.0 code injection (EUVD-2026-28549 / WID-SEC-2026-1438)
A vulnerability has been found in Apache CloudStack up to 4.20.2.0/4.22.0.0 and classified as critical. This impacts an unknown function. Performing a manipulation results in code injection.
This vulnerability is known as CVE-2026-25077. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.