Race condition in Extreme Platform ONE - CVE-2026-9831
Published: June 1, 2026
Extreme Platform ONE
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information across tenants.
The vulnerability exists due to a race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path when handling high-concurrency requests to affected API endpoints. A remote user can send concurrent requests authenticated with an IAM-issued API key to disclose sensitive information across tenants.
XIQ-native tokens and standard OAuth/Bearer JWT authentication are not affected.