Extreme Networks · Extremecloud Iq · CVE-2026-9831
**Name of the Vulnerable Software and Affected Versions**
ExtremeCloud IQ (affected versions not specified)
**Description**
A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path can intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data belonging to another tenant under high-concurrency traffic conditions. This issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. This flaw has been exploited in real-world incidents to access cross-tenant data.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.