
Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.
Apache CloudStack 4.16.0 and later versions have a broken access control issue that allows users with knowledge of resource UUIDs to read or add comments (annotations) on resources they are not authorized to access. UUIDs can be exposed in various parts of the application, such as when a user initially has access to a resource but later loses it due to administrative restrictions.
The CVE-2025-22828 vulnerability was discovered by Alex Perrakis (Stolichnayer).