CVE-2026-88263: High severity XikeStor Layer3 switches vulnerability
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access so unauthenticated clients cannot download configuration data (network configurations and passwords) from XikeStor Layer3 switches; require authentication for configuration-data retrieval.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it over the network. No privileges or user interaction are required.
What information could be exposed?
The attacker may download configuration data, including network configuration details and passwords. The disclosed information could be used to operate the switch improperly or use it as a jump host.
Does exploitation modify or disrupt the switch?
The provided severity vector indicates high confidentiality impact, with no integrity or availability impact stated. The described issue is configuration-data disclosure rather than a configuration change or denial of service.