Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Based Access Control. For more details, see:

https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles

The pool-admin role is fully privileged. Notably, users with this role
can also SSH into the host as root.

The other administrator roles are pool-operator, vm-power-admin and
vm-admin, each of which are authorised to configure and manage various
aspects of the system.

Some settings are inadequately restricted, and can be set by a lower
privilege of administrator than expected.

* CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and
turn arbitrary files in dom0 into VDIs (virtual disks) and give said
disks to a VM they control. This is an arbitrary read and/or modify
of files in dom0.

* CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain
and mark a VM as a system domain. System domains are ignored and
left running during certain other host/pool operations, and may be
hidden from view in tooling.

* CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain
and mark a VM as the storage domain for a particular host storage
connection (PBD). Shutting down the VM can cause the PBD to be
erroneously marked as unplugged when it is not.

* CVE-2026-23562: Configuration of PCI passthrough is normally
restricted to the pool-admin role. However one API was missing this
check, allowing a vm-admin access to unintended host hardware.

* CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial
parameter, which should be restricted to the pool-admin role, as it
can allow arbitrary dom0 file write.
Published: 2026-07-09
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

VM administrators are able to set the VM.other‑config:is_system_domain flag, a setting that should be restricted to higher‑privilege pool administrators. When a VM is marked as a system domain it can be hidden from management tools and ignored during certain host or pool operations, providing a stealthy foothold for the attacker. This flaw effectively grants a lower‑privilege administrator the ability to alter system‑critical configurations, potentially leading to denial against the host if the marked VM interferes with normal operation. The weakness constitutes a CWE‑250 "Privilege‑Controlled Missing or Incorrect Authorization" vulnerability.

Affected Systems

The vulnerability affects Xen XAPI, the role‑based access control component of Xen Server. Users with the vm‑admin role on any Xen Server deployment can exploit the flaw, regardless of the specific Xen version, as the product documentation does not state any version restrictions. No specific version information is provided in the CNA data, so all XAPI installations that include the exposed API call are potentially impacted.

Risk and Exploitability

With a CVSS score of 9.4 the flaw is considered critical, and the EPSS score of < 1 % indicates a low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, and the as a vm-admin. An attacker with marking VMs as system domains, thereby bypassing intended administrative boundaries and potentially disrupting host or pool operations.

Generated by OpenCVE AI on July 29, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Xen Server to a release that removes the API surface allowing vm‑admin role any permissions that enable modification of VM.other_config entries, restricting the role to only the required management tasks.
  • Monitor API and system logs for attempts to set VM.other-config:is_system_domain and configure alerts for unauthorized changes.
  • Restrict the vm-admin role to users who strictly require it; consider revoking or limiting this role for users without necessity to modify system-critical configurations.
  • Apply patches and updates as recommended in the XSA‑489 advisory to ensure the RBAC restrictions are enforced.

Generated by OpenCVE AI on July 29, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Xen
Xen xapi
Vendors & Products Xen
Xen xapi

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
Title Multiple RBAC issues in XAPI
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2026-07-09T16:08:13.898Z

Reserved: 2026-01-14T13:07:36.961Z

Link: CVE-2026-23560

cve-icon Vulnrichment

Updated: 2026-07-09T16:08:09.527Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges