CVE-2025-66467High· 8.0▾ TwilightMissing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorize…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated access and secret keys.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
cloudstack >= 4.19.0.0, < 4.20.3.0cloudstack >= 4.21.0.0, < 4.22.0.1Upgrade past the affected range:
cloudstack 4.22.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-69233Medium· 6.5Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domai…
CVE-2025-66171Medium· 6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-66172High· 8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-66170Medium· 6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0
CVE-2026-11576High· 7.5The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
CVE-2025-53648Medium· 5.4SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue.