Junglewise Threat Intelligence

CVE-2026-0689: Extreme Networks ExtremeCloud IQ , Site Engine credential exposure in NAC interface

CVE-2026-0689 · Severity: medium · CVSS 4.9 · Published 2026-03-02

Executive brief

ExtremeCloud IQ – Site Engine is a management platform used to control and monitor network infrastructure. A security flaw in its administration interface allows authorized administrators to view sensitive credentials that should be hidden. This could allow a user with administrative access to gain additional secrets or passwords they are not supposed to see, potentially leading to unauthorized access to other parts of the network.

Technical details

An information disclosure vulnerability exists in the NAC administration interface of ExtremeCloud IQ – Site Engine (XIQ‑SE) before version 26.2.10. The root cause is insufficient protection of credentials (CWE-522) where sensitive parameters are masked in the web UI but transmitted in plaintext or unredacted form within the underlying HTTP responses. An authenticated NAC administrator can intercept or inspect these responses to recover stored secrets. This vulnerability requires high privileges (PR:H) and is reachable over the network. The issue is resolved in version 26.2.10.

Affected products

  • Extreme Networks ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10

Timeline

  • 2026-03-02: disclosed
  • 2026-03-02: advisory
  • 2026-03-02: patched: Fixed in version 26.2.10

References