CVE-2026-9831: ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable Extreme Platform ONE /IAM-issued API-key authentication on the IAM Gateway until a vendor patch or guidance is available to prevent potential cross-tenant response data exposure.
Extreme Platform ONE IAM Gateway API-key authentication api_key_auth_enabled = false - Configuration
Migrate clients and integrations to use XIQ-native tokens or standard OAuth/Bearer JWT authentication, as these methods were not affected by the reported race condition.
ExtremeCloud IQ / API authentication preferred_auth_methods = XIQ-native tokens, OAuth/Bearer JWT
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9831?
The severity of CVE-2026-9831 is medium, with a score of 6.3.
What does CVE-2026-9831 affect?
CVE-2026-9831 affects Extreme Networks Extreme Platform ONE and Extreme Networks ExtremeCloud IQ.
What type of vulnerability is CVE-2026-9831?
CVE-2026-9831 is categorized as a race condition vulnerability.
How do I fix CVE-2026-9831?
To fix CVE-2026-9831, ensure that you apply any security patches or updates provided by Extreme Networks.
What can happen if CVE-2026-9831 is exploited?
If exploited, CVE-2026-9831 can lead to cross-tenant data exposure, allowing unauthorized access to another tenant's data.