Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-47849

8.8 · HIGH
Published Jun 10, 2025 apache CWE-269 EPSS 0.55% (44th pctl)

Overview

CVE-2025-47849 is a high-severity vulnerability affecting apache cloudstack. It was published on June 10, 2025 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastructure managed by CloudStack.

Users are recommended to upgrade to Apache CloudStack 4.19.3.0 or 4.20.1.0, which fixes the issue with the following:

* Strict validation on Role Type hierarchy: the caller's role must be equal to or higher than the target user's role. 

* API privilege comparison: the caller must possess all privileges of the user they are operat

Remediation

Check the references section for vendor advisories and patches from apache. Update cloudstack to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
apache cloudstack >= 4.10.0.0, < 4.19.3.0 Affected

Frequently Asked Questions

What is CVE-2025-47849?

CVE-2025-47849 is a high-severity vulnerability affecting apache cloudstack. It was published on June 10, 2025 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2025-47849?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-47849?

Check the references section for vendor advisories and patches from apache. Update cloudstack to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-47849?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-47849 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.