Improper access control in XenAPI Server - CVE-2026-23559

 

Improper access control in XenAPI Server - CVE-2026-23559

Published: April 29, 2026


Vulnerability identifier: #VU128446
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23559
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read and modify arbitrary files in dom0.

The vulnerability exists due to improper access control in VBD.other_config:backend-local handling when configuring a virtual block device. A remote user can set the backend-local option to turn arbitrary files in dom0 into virtual disks and attach them to a VM they control to read and modify arbitrary files in dom0.

The vulnerability is exposed only when RBAC is configured for the pool.


Affected software

XenAPI Server
Citrix XenServer

How to mitigate CVE-2026-23559

Install security update from vendor's website.


External References

Related Security Bulletins