https://seclists.org/oss-sec/2026/q2/253: Xen Security Advisory 489 v1 (CVE-2026-23559,CVE-2026-23560,CVE-2026-23561,CVE-2026-23562,CVE-2026-42486) - Multiple RBAC issues in XAPI
Published Apr 28, 2026
·Updated
Affected Software
1 affected component
Xen Project xen-api (XAPI)
Frequently Asked Questions
1
What is the severity of CVE-2026-23559?
CVE-2026-23559 is classified as a critical vulnerability due to its potential to impact access control in XAPI.
2
How do I fix CVE-2026-23560?
To mitigate CVE-2026-23560, users should upgrade to the latest version of Xen Project that addresses this RBAC issue.
3
What systems are affected by CVE-2026-23561?
CVE-2026-23561 affects the Xen Project's XAPI, specifically installations configured with Role Based Access Control.
4
What are the implications of CVE-2026-23562?
CVE-2026-23562 could allow unauthorized users to gain access to sensitive operations, compromising the security of the system.
5
Are there any workarounds for CVE-2026-42486?
There are no effective workarounds for CVE-2026-42486; upgrading to the patched version is the recommended solution.