Improper access control in XenAPI Server - CVE-2026-23560
Published: April 29, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in VM.other-config:is_system_domain when modifying VM configuration. A remote user can mark a VM as a system domain to escalate privileges.
System domains may be ignored and left running during certain host or pool operations, and may be hidden from view in tooling.
Affected software
Citrix XenServer