Apache CloudStack LDAP Config Disclosure Before 4.20.3.1 / 4.22.1.1
CVE-2026-59780 Published on August 21, 2026

Apache CloudStack: LDAP provider configuration disclosure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles. This issue affects Apache CloudStack: from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Vendor Advisory NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-59780 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-59780

Want to know whenever a new CVE is published for Apache CloudStack? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache CloudStack: