Apache CloudStack LDAP Config Disclosure Before 4.20.3.1 / 4.22.1.1
CVE-2026-59780 Published on August 21, 2026
Apache CloudStack: LDAP provider configuration disclosure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers.
LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles.
This issue affects Apache CloudStack: from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-59780 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-59780
Want to know whenever a new CVE is published for Apache CloudStack? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache CloudStack:- Version 4.2.0.0, <= 4.20.3.0 is affected.
- Version 4.21.0.0, <= 4.22.1.0 is affected.