Improper access control in XenAPI Server - CVE-2026-42486
Published: April 29, 2026
XenAPI Server
Xen Project
Description
The vulnerability allows a remote user to write arbitrary files in dom0.
The vulnerability exists due to improper access control in VM.platform:hvm_serial when modifying VM platform parameters. A remote user can set the hvm_serial parameter to write arbitrary files in dom0.
The vulnerability is exposed only when RBAC is configured for the pool.