CVE-2015-6861: Eucalyptus

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.

Affected products

  • Eucalyptus Eucalyptus: version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; version 3.4.3 only; version 4.0.0 only; version 4.0.1 only; …

Published 2016-01-05. Last modified 2026-06-17.