This is a security release that fixes the following on top of the 4.22.1.0 release:
CVE-2026-47359: OS Command Injection due to unsanitized mount command
CVE-2026-50112: RCE and SSRF in direct download, metalink and NFS templates
CVE-2026-50222: Improper access control in Userdata reference APIs
CVE-2026-59085: Server-Side Request Forgery (SSRF) vulnerability in webhook module
CVE-2026-59654: DoS caused by database connections leak
CVE-2026-59655: Unauthenticated OAuth provider client-secret disclosure
CVE-2026-59657: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
CVE-2026-59780: LDAP provider configuration disclosure
CVE-2026-59799: Missing Privilege Check in Two-Factor Authentication Disable Flow
CVE-2026-61397: OAuth2 Token Cross-Request Leak
CVE-2026-61398: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UI
CVE-2026-61399: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UI
CVE-2026-61400: Get and Run Diagnostics Command Injection
CVE-2026-61422: Authenticated pre-validation SSRF in registerTemplate
CVE-2026-62440: Improper access control in Kubernetes Service (CKS) cluster manipulation
CVE-2026-65613: Webhook Deliveries Incorrect Access
CVE-2026-66721: Authorization issue with listHostTags for domain admins
CVE-2026-66722: ProjectRole & ProjectRolePermission authorization issue
CVE-2026-66797: Unauthorised comment creation and disclosure
CVE-2026-68745: SAML2 Signature Validation Silently Skipped for Cert-less IdP
Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.20.3.1-4.22.1.1/
Release notes: https://docs.cloudstack.apache.org/en/4.22.1.1/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.22.1.1/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.22.1.1/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.22.1.1/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.22