Improper Certificate Validation in Xen - CVE-2026-42491

 

Improper Certificate Validation in Xen - CVE-2026-42491

Published: July 14, 2026


Vulnerability identifier: #VU137514
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42491
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to intercept communications and disclose sensitive information or tamper with data in transit.

The vulnerability exists due to improper certificate validation in HTTP handlers in the XAPI C# and Powershell SDKs when opening a separate connection to the XAPI host. A remote attacker can perform a man-in-the-middle attack on network communication to intercept communications and disclose sensitive information or tamper with data in transit.

Successful exploitation may expose a session token and affect exported or imported disk images, host backups, RRD performance data, and patches or updates transferred over these connections.


Affected software

Xen
Citrix XenServer

How to mitigate CVE-2026-42491

Install security update from vendor's website.

Citrix XenServer - update to 2026.4.0

External References

Related Security Bulletins