CVE-2026-47359

Source
https://cve.org/CVERecord?id=CVE-2026-47359
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47359.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47359
Published
2026-08-21T08:30:07.701Z
Modified
2026-08-28T11:47:29.415261143Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache CloudStack: OS Command Injection due to unsanitized mount command
Details

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0) accept unsanitized command options for the backup repository. A malicious operator account can exploit this to inject arbitrary commands that execute on the KVM hypervisor host when any account subsequently performs a backup restore.

This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.

Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47359.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.20.0.0"
                },
                {
                    "last_affected": "4.20.3.0"
                },
                {
                    "introduced": "4.21.0.0"
                },
                {
                    "last_affected": "4.22.1.0"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "4.20.0.0"
                },
                {
                    "fixed": "4.20.3.0"
                },
                {
                    "introduced": "4.21.0.0"
                },
                {
                    "fixed": "4.22.1.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-78"
    ],
    "cna_assigner": "apache"
}
References

Affected packages

Git / github.com/apache/cloudstack

Affected ranges

Type
GIT
Repo
https://github.com/apache/cloudstack
Events
Database specific
Show details
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "4.20.0.0"
        },
        {
            "fixed": "4.20.3.0"
        },
        {
            "introduced": "4.21.0.0"
        },
        {
            "fixed": "4.22.1.0"
        }
    ]
}

Affected versions

4.*
4.20.0.0
4.20.1.0
4.21.0.0
4.22.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47359.json"