CVE-2026-42486: Multiple RBAC issues in XAPI
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see:
https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles
The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root.
The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system.
Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected.
CVE-2026-23559: A vm-admin can set VBD.otherconfig:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0.
CVE-2026-23560: A vm-admin can set VM.other-config:issystemdomain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling.
CVE-2026-23561: A vm-admin can set VM.otherconfig:storagedriverdomain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not.
CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware.
CVE-2026-42486: A vm-admin can set the VM.platform:hvmserial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42486?
CVE-2026-42486 is classified with a medium severity due to potential unauthorized access implications.
How do I fix CVE-2026-42486?
To fix CVE-2026-42486, update your Xen Project XAPI to the latest version where the vulnerabilities are patched.
What should I do if I cannot apply the fix for CVE-2026-42486 immediately?
If you cannot apply the fix for CVE-2026-42486 immediately, implement additional access controls to mitigate the risks until the update is applied.
Which versions of Xen Project XAPI are affected by CVE-2026-42486?
CVE-2026-42486 affects specific versions of Xen Project XAPI that have not been updated since the vulnerability was identified.
Are there any workarounds for CVE-2026-42486 before applying the patch?
Currently, there are no recommended workarounds for CVE-2026-42486, and it is advised to apply the patch as soon as possible.