Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]


XAPI can configure different users with different roles, using Role
Based Access Control. For more details, see:

https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles

The pool-admin role is fully privileged. Notably, users with this role
can also SSH into the host as root.

The other administrator roles are pool-operator, vm-power-admin and
vm-admin, each of which are authorised to configure and manage various
aspects of the system.

Some settings are inadequately restricted, and can be set by a lower
privilege of administrator than expected.

* CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and
turn arbitrary files in dom0 into VDIs (virtual disks) and give said
disks to a VM they control. This is an arbitrary read and/or modify
of files in dom0.

* CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain
and mark a VM as a system domain. System domains are ignored and
left running during certain other host/pool operations, and may be
hidden from view in tooling.

* CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain
and mark a VM as the storage domain for a particular host storage
connection (PBD). Shutting down the VM can cause the PBD to be
erroneously marked as unplugged when it is not.

* CVE-2026-23562: Configuration of PCI passthrough is normally
restricted to the pool-admin role. However one API was missing this
check, allowing a vm-admin access to unintended host hardware.

* CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial
parameter, which should be restricted to the pool-admin role, as it
can allow arbitrary dom0 file write.
Published: 2026-07-09
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑23559 allows a user with the vm‑admin role to set the VBD.other_config:backend‑local flag, turning arbitrary files in the host domain into virtual disks that can be attached to a VM under the attacker's control. This effectively provides read and write access to any file on the host, allowing critical system configuration or sensitive data to be exfiltrated or modified. The related CVEs expand the scope of the privilege misuse to system domain marking, storage domain mis‑configuration, unexpected PCI passthrough access, and a serial port device that should be restricted to full‑admin users. The weakness is a classic elevation of privilege flaw (CWE‑250) wherein lower‑privileged administrative roles are granted higher‑level capabilities.

Affected Systems

The vulnerability resides in Xen XAPI’s role‑based access control system. Any installation of XAPI that assigns users the vm‑admin role without further restrictions is potentially impacted; all supported XenServer releases that provide these roles are affected until patched by the vendor.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, yet the vulnerability could still be widely exploitable given its nature. The flaw is not listed in CISA KEV catalog, yet it remains a high‑risk privilege escalation exploit. A likely attack vector is via an authenticated XAPI API call from a user possessing the vm‑admin role; this is inferred from the documented API usage.

Generated by OpenCVE AI on July 29, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch or upgrade to the latest XenServer release that fixes the admin roles
  • Temporarily revoke or re‑configure the vm‑admin role for all users except those who strictly require it, enforcing least‑privilege principles
  • Enable security auditing for XAPI API calls and monitor attempts to set restricted VFD or VM.other_config settings, proactively blocking unauthorized actions

Generated by OpenCVE AI on July 29, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Xen
Xen xapi
Vendors & Products Xen
Xen xapi

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
Title Multiple RBAC issues in XAPI
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2026-07-09T16:02:32.186Z

Reserved: 2026-01-14T13:07:36.961Z

Link: CVE-2026-23559

cve-icon Vulnrichment

Updated: 2026-07-09T16:02:28.563Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges