PT-2026-42282 · Xen+3 · Xapi+3

CVE-2026-23560

·

Published

2026-04-20

·

Updated

2026-07-10

CVSS v4.0

9.4

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions XCP-ng (affected versions not specified) XenServer (affected versions not specified) Xen XAPI (affected versions not specified)
Description A role-based access control (RBAC) flaw exists in the Xen XAPI subsystem, specifically within the system domains.ml:30-35() function. The issue stems from improper authorization and insufficient access control regarding sensitive VM configurations. An attacker with vm-admin privileges can manipulate the VM.other-config:is system domain variable to classify a virtual machine as a system domain. This allows the VM to be ignored during certain host or pool operations, effectively hiding it from management tools. Such exploitation can lead to unauthorized privilege escalation to root level, persistence, and evasion of operational controls, allowing unauthorized workloads to survive maintenance actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07088
CVE-2026-23560

Affected Products

Xapi
Xcp-Ng
Xenserver
Xen