VDB

GCVE-110-NCSC-2026-332

GCVE-110-NCSC-2026-332
Advisory PublishedCVSS 8.1/10
Vulnetix · Advisory published August 27, 2026
Apache CloudStack versions 4.20.0.0 to 4.20.3.0 and 4.21.0.0 to 4.22.1.0 contain an OS Command Injection vulnerability in the NAS backup provider plugin allowing arbitrary command execution on KVM hypervisor hosts during backup restore.

Weaknesses (CWE)

CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-862Missing AuthorizationCWE-918Server-Side Request Forgery (SSRF)CWE-312Cleartext Storage of Sensitive InformationCWE-116Improper Encoding or Escaping of OutputCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-347Improper Verification of Cryptographic Signature

Risk Scores

CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Apache Software Foundationvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›