Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures.
Users are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue.
CVE-2026-68745
NONE
EPSS 0.07%
Updated Aug 21, 2026
Apache Software Foundation
apache software foundation:apache cloudstack
CVE Details
CVE ID
CVE-2026-68745
Published Date
Aug 21, 2026
Vendor
Apache Software Foundation
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.07%
Likelihood of exploitation in next 30 days
Percentile:
0.1th percentile (higher than 0.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory