Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sebastian Koller

#42626of 53,635
6.3Total CVSS
Vulnerabilities · 1
PT-2026-44998
6.3
2026-05-29
Extreme Networks · Extremecloud Iq · CVE-2026-9831
**Name of the Vulnerable Software and Affected Versions** ExtremeCloud IQ (affected versions not specified) **Description** A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path can intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data belonging to another tenant under high-concurrency traffic conditions. This issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. This flaw has been exploited in real-world incidents to access cross-tenant data. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.