Cleartext Storage via AsyncJob DB in Apache CloudStack 4.0.0-4.22.1.0
CVE-2026-59657 Published on August 21, 2026

Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Vendor Advisory NVD

Weakness Type

Cleartext Storage of Sensitive Information

The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Because the information is stored in cleartext, attackers could potentially read it. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.


Products Associated with CVE-2026-59657

Want to know whenever a new CVE is published for Apache CloudStack? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache CloudStack: