Junglewise Threat Intelligence

CVE-2026-23559: Xen Project XAPI privilege escalation via VBD configuration

CVE-2026-23559 · Severity: info · CVSS 9.4 · Published 2026-07-09

Vendors: Xen Project.

Executive brief

A security flaw in the Xen Project's XAPI management tool allows users with restricted administrative roles to bypass security controls. By manipulating specific virtual disk settings, an attacker with limited access can read or modify sensitive files on the host server. This could lead to a complete takeover of the virtualization host and unauthorized access to data from other virtual machines.

Technical details

A vulnerability in XAPI's Role Based Access Control (RBAC) implementation allows a user with the 'vm-admin' role to escalate privileges. Specifically, the 'VBD.other_config:backend-local' parameter is inadequately restricted, allowing an attacker to map arbitrary files from the privileged control domain (dom0) as virtual disks (VDIs) and attach them to a virtual machine they control. This results in arbitrary read and write access to host-level files. The issue is resolved in XAPI releases v26.1.11 and v26.12.0.

Affected products

  • Xen Project XAPI All versions prior to v26.1.11 and v26.12.0

Timeline

  • 2026-04-28: disclosed: Initial public release of XSA-489
  • 2026-04-29: patched: Version 2 of advisory confirms fixes merged and backported
  • 2026-07-09: advisory: NVD publication date

References