CVE-2026-68745
Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.
| CWE | CWE-347 |
| Vendor | apache software foundation |
| Product | apache cloudstack |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache cloudstack
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cloudstack are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache CloudStack
4.5.2 โค 4.20.3.0 4.21.0.0 โค 4.22.1.0
References
Credits
๐ Katriel Moses <[email protected]>