CVE-2026-65613

NONE EPSS 0.14%
Updated Aug 21, 2026
Apache Software Foundation
Parameter Value
Affected Versions 4.20.0.0 — 4.20.3.0
Fixed In 4.20.3.1
Type CWE-200 (Information Exposure), CWE-284 (Improper Access Control)
Vendor Apache Software Foundation
Public PoC No

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Vulnerable Products

apache software foundation:apache cloudstack