Junglewise Threat Intelligence

CVE-2026-23561: Xen Project XAPI privilege escalation in storage domain configuration

CVE-2026-23561 · Severity: info · CVSS 9.4 · Published 2026-07-09

Vendors: Xen Project.

Executive brief

A vulnerability in the Xen Project's XAPI management tool allows users with restricted administrative roles to disrupt storage connections. By misconfiguring a virtual machine as a storage domain, an attacker can cause storage connections to be incorrectly marked as disconnected when the machine is shut down. This can lead to service interruptions and operational instability within the virtualized environment.

Technical details

A vulnerability exists in XAPI's Role Based Access Control (RBAC) implementation where the 'VM.other_config:storage_driver_domain' parameter is inadequately restricted. An authenticated user with the 'vm-admin' role can set this parameter to mark a VM as the storage domain for a specific Physical Block Device (PBD) connection. When the attacker-controlled VM is shut down, XAPI erroneously marks the associated PBD as unplugged, potentially disrupting storage access for the host. This issue is part of a broader set of RBAC bypasses (XSA-489) and has been addressed in XAPI releases v26.12.0 and v26.1.11.

Affected products

  • Xen Project XAPI All versions prior to v26.12.0 and v26.1.11

Timeline

  • 2026-04-28: disclosed: Initial public release of XSA-489
  • 2026-04-29: patched: Version 2 of advisory released with fix information
  • 2026-07-09: advisory: NVD publication date

References