CVE-2026-23560Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Xen XAPI RBAC bypass lets vm-admin mark VMs as “system domains” (CVE-2026-23560) CVE-2026-23560 is a role-based access control flaw in Xen XAPI where permissions don’t properly gate sensitive VM configuration, specifically VM.other-config:is_system_domain. The root cause is improper authorization/insufficient access control (RBAC misconfiguration) allowing a lower-privileged role to change a setting intended for higher-privileged administrators. An attacker with vm-admin access can set is_system_domain to classify a VM as a system domain so it’s ignored during certain host/pool operations and may be effectively hidden from management tooling. Impact includes persistence and evasion of operational controls, leading to unauthorized workloads surviving maintenance actions and undermining governance and incident response. 👉 Affected: Xen XAPI (versions not specified) | Upgrade to Vendor fix (not yet specified)

    Post summary

    CVE-2026-23560 exposes a critical RBAC bypass in Xen XAPI enabling vm‑admin users to mark VMs as system domains, bypassing host/pool operations; a vendor fix is pending.

    0000085
    246 followersView on X

Explore more