Junglewise Threat Intelligence

CVE-2026-9831: Extreme Networks Extreme Platform ONE race condition in IAM Gateway

CVE-2026-9831 · Severity: medium · CVSS 6.3 · Published 2026-05-29

Executive brief

A security flaw in the Extreme Networks cloud management platform could allow one customer to accidentally view data belonging to another customer. This issue occurs intermittently during periods of very high system traffic when using specific API key authentication. While it does not allow an attacker to choose whose data they see, it poses a risk to data privacy and multi-tenant isolation.

Technical details

A race condition (CWE-362) exists in the shared Extreme Platform ONE IAM Gateway API-key authentication path. Under conditions of high-concurrency traffic, the gateway may improperly synchronize shared resources, leading to the exposure of a data element to the wrong session (CWE-488). This allows a request authenticated with a valid IAM-issued API key to intermittently receive response data intended for a different tenant. The vulnerability specifically affects the XIQ/XAPI and Common Services API paths; notably, XIQ-native tokens and standard OAuth/Bearer JWT authentication methods are not impacted. Exploitation requires the attacker to have a valid API key and for the system to be under specific high-load conditions.

Affected products

  • Extreme Networks Extreme Platform ONE IAM Gateway
  • Extreme Networks ExtremeCloud IQ (XIQ)

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References