Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-62440

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.9%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-62440


Contact Us

Shodan ® - All rights reserved