๐Ÿ” CVE Alert

CVE-2026-68745

UNKNOWN 0.0

Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures. Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.

CWE CWE-347
Vendor apache software foundation
Product apache cloudstack
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache cloudstack

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cloudstack are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache CloudStack
4.5.2 โ‰ค 4.20.3.0 4.21.0.0 โ‰ค 4.22.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc

Credits

๐Ÿ” Katriel Moses <[email protected]>