Cleartext Storage via AsyncJob DB in Apache CloudStack 4.0.0-4.22.1.0
CVE-2026-59657 Published on August 21, 2026
Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database.
This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Weakness Type
Cleartext Storage of Sensitive Information
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Because the information is stored in cleartext, attackers could potentially read it. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Products Associated with CVE-2026-59657
Want to know whenever a new CVE is published for Apache CloudStack? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache CloudStack:- Version 4.0.0, <= 4.20.3.0 is affected.
- Version 4.21.0.0, <= 4.22.1.0 is affected.