https://seclists.org/oss-sec/2026/q2/276: Xen Security Advisory 489 v2 (CVE-2026-23559,CVE-2026-23560,CVE-2026-23561,CVE-2026-23562,CVE-2026-42486) - Multiple RBAC issues in XAPI
Published Apr 29, 2026
·Updated
Affected Software
1 affected component
Xen Project XAPI<26.12.0, <26.1.11
Frequently Asked Questions
1
What is the severity of CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486?
The vulnerabilities are considered high severity due to their potential impact on role-based access control in XAPI.
2
How do I fix CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486?
To fix these vulnerabilities, update to the latest version of Xen Project XAPI where the backported fixes have been merged.
3
What components are affected by CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486?
The affected component is the XAPI, which manages the lifecycle and management of virtual machines in Xen Project.
4
What types of issues do CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486 represent?
These vulnerabilities represent multiple role-based access control issues that can lead to unauthorized access.
5
When was Xen Security Advisory 489 published?
Xen Security Advisory 489 was published on April 29, 2026.