CVE-2026-61397

NONE EPSS 0.17%
Updated Aug 21, 2026
Apache Software Foundation
Parameter Value
Affected Versions 4.19.0.0 — 4.20.3.0
Fixed In 4.20.3.1
Type CWE-200 (Information Exposure)
Vendor Apache Software Foundation
Public PoC No

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue.

Weakness Type (CWE)

Vulnerable Products

apache software foundation:apache cloudstack