Improper access control in XenAPI Server - CVE-2026-23562
Published: April 29, 2026
XenAPI Server
Xen Project
Description
The vulnerability allows a remote user to access unintended host hardware.
The vulnerability exists due to improper access control in a PCI passthrough API when configuring PCI passthrough. A remote user can invoke the API without the intended pool-admin restriction to access unintended host hardware.
The vulnerability is exposed only when RBAC is configured for the pool.