VDB
GCVE-110-NCSC-2026-332
GCVE-110-NCSC-2026-332
Advisory PublishedCVSS 8.1/10
Apache CloudStack versions 4.20.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0 contain an OS Command Injection vulnerability in the NAS backup provider plugin allowing arbitrary command execution on KVM hypervisor hosts during backup restore.
Weaknesses (CWE)
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-862Missing AuthorizationCWE-918Server-Side Request Forgery (SSRF)CWE-312Cleartext Storage of Sensitive InformationCWE-116Improper Encoding or Escaping of OutputCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-347Improper Verification of Cryptographic Signature
Risk Scores
CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apache Software Foundation | vers:unknown/* | — | — |
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.