CVE-2026-23560: Multiple RBAC issues in XAPI
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see:
https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles
The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root.
The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system.
Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected.
CVE-2026-23559: A vm-admin can set VBD.otherconfig:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0.
CVE-2026-23560: A vm-admin can set VM.other-config:issystemdomain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling.
CVE-2026-23561: A vm-admin can set VM.otherconfig:storagedriverdomain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not.
CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware.
CVE-2026-42486: A vm-admin can set the VM.platform:hvmserial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23560?
CVE-2026-23560 is classified as a high severity vulnerability due to its potential impact on role-based access control.
How do I fix CVE-2026-23560?
To fix CVE-2026-23560, update your Xen Project XAPI to the latest version where the vulnerability has been patched.
What are the risks associated with CVE-2026-23560?
The risks associated with CVE-2026-23560 include unauthorized access and manipulation of resources within the Xen Project environment.
Does CVE-2026-23560 affect all versions of Xen Project XAPI?
CVE-2026-23560 affects specific versions of Xen Project XAPI; it is important to check the advisory for details on affected versions.
Are there any workarounds for CVE-2026-23560?
There are no recommended workarounds for CVE-2026-23560; applying the patch is the suggested solution.