External risk intelligence

Apache CloudStack CKS Cross-Tenant Kubernetes Cluster Manipulation

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-62440

The vulnerability exists within the Apache CloudStack Kubernetes Service plugin, which manages backend infrastructure. While the management interface of CloudStack is often network-accessible, the specific manipulation of tenant Kubernetes clusters usually requires authenticated access to the management layer rather than being a public-facing endpoint by design.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts the Kubernetes Service plugin for Apache CloudStack, potentially allowing unauthorized users to manipulate Kubernetes clusters, including adding or removing nodes, across different tenants. While the primary concern is confirming relevance and exposure, understanding this type of cross-tenant manipulation is key.

  • Cross-tenant Kubernetes cluster manipulation is possible.
  • Affects Apache CloudStack's Kubernetes Service plugin.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise a Kubernetes cluster managed by Apache CloudStack's Kubernetes Service (CKS) plugin. This would involve exploiting an improper access control flaw within the plugin, which could allow for unauthorized manipulation of the cluster, including actions like adding or removing nodes. The vulnerability could enable an attacker to affect resources across different tenants.

  • No authentication required for entry.
  • Manipulate Kubernetes nodes.
  • Cross-tenant cluster control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to manipulate Kubernetes clusters belonging to other tenants within Apache CloudStack when adding or removing nodes. This is possible when the Kubernetes Service (CKS) plugin is used and when supported by the advisory.

  • Tenant Kubernetes cluster data
  • Cross-tenant manipulation of cluster nodes
  • Unauthorized cluster resource access

Operational Fix

Recommended remediation, mitigation, and detection steps

The Apache CloudStack Kubernetes Service (CKS) plugin's Improper Access Control vulnerability likely falls under the responsibility of platform or infrastructure teams managing CloudStack, in coordination with security and vendor management teams. The immediate first step is to identify all instances of the affected CKS plugin, confirm their exposure and criticality, and then assign ownership for remediation planning.

  • Platform/Infrastructure teams own the issue.
  • Verify CKS plugin reachability and criticality.
  • Plan coordinated upgrade during maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Apache CloudStack Kubernetes Service (CKS) plugin?

The CKS plugin is a component within Apache CloudStack that automates the deployment and management of Kubernetes clusters. It acts as an abstraction layer, allowing administrators to provision and scale container orchestration environments directly through their existing cloud infrastructure.

What does CVE-2026-62440 mean by improper access control?

This vulnerability is classified as Improper Access Control (CWE-284). It means the software fails to properly verify if a user has the correct permissions before performing sensitive actions. In this case, the CKS plugin does not correctly enforce boundaries, allowing unauthorized users to interact with clusters they do not own.

How can an attacker trigger this vulnerability?

An attacker can exploit this by interacting with the affected CKS plugin to issue commands as if they were a legitimate administrator. Notably, the vulnerability does not require the attacker to have existing valid credentials for the target tenant's environment to initiate these unauthorized node modifications.

Is my Apache CloudStack instance at risk?

Halo Surface Signal indicates that while the management interface of CloudStack is often network-accessible, direct exploitation usually requires reaching the internal management layer. You should prioritize checking if your deployment uses the affected 4.21.0.0 through 4.22.1.0 versions of the Kubernetes Service plugin.

How do I remediate this vulnerability?

The primary response is to update your Apache CloudStack environment to version 4.22.1.1 or later. Your infrastructure team should verify the version currently in use across your deployments, coordinate a maintenance window, and apply the vendor-provided update to secure the CKS plugin.

References