SB2026043083 - Two vulnerabilities in Citrix XenServer
Published: April 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-23562)
The vulnerability allows a remote user to access unintended host hardware.
The vulnerability exists due to improper access control in a PCI passthrough API when configuring PCI passthrough. A remote user can invoke the API without the intended pool-admin restriction to access unintended host hardware.
The vulnerability is exposed only when RBAC is configured for the pool.
2) Improper access control (CVE-ID: CVE-2026-42486)
The vulnerability allows a remote user to write arbitrary files in dom0.
The vulnerability exists due to improper access control in VM.platform:hvm_serial when modifying VM platform parameters. A remote user can set the hvm_serial parameter to write arbitrary files in dom0.
The vulnerability is exposed only when RBAC is configured for the pool.
Remediation
Install update from vendor's website.