Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-22828 — Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources. | Kitploit
Tools/GitHubGitHub/stolichnayer/cve-2025-22828
Vulnerability AnalysisExploitationInformation GatheringCloud SecurityMisconfiguration
GitHubstolichnayer/cve-2025-22828

CVE-2025-22828

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

View Repository
421 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-22828

📜 Description

Apache CloudStack 4.16.0 and later versions have a broken access control issue that allows users with knowledge of resource UUIDs to read or add comments (annotations) on resources they are not authorized to access. UUIDs can be exposed in various parts of the application, such as when a user initially has access to a resource but later loses it due to administrative restrictions.

🔍 Vulnerability Details

  • Type: Broken Access Control
  • Impact: Unauthorized access to annotations and potentially sensitive data
  • Affected Versions: 4.16.0 and later
  • CWE: Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)

🎬 Demonstration Videos

Unauthorized Access to Annotations (listAnnotations command)

Unauthorized Adding of Annotations (addAnnotations command)

🧑‍💻 Discovery

The CVE-2025-22828 vulnerability was discovered by Alex Perrakis (Stolichnayer).

🔗 References

  • CVE-2025-22828 on Apache CloudStack Blog
  • CVE-2025-22828 on CVE Program
  • CVE-2025-22828 on NIST
Download Tool