CVE-2026-42486
Last modified
CVE-2026-42486 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.
Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Xen | XAPI | all |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42486?
How severe is CVE-2026-42486?
How do I fix CVE-2026-42486?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42480A stack-based out-of-bounds read vulnerability in VrmlData_S…5.5
- CVE-2026-42481Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple …5.5
- CVE-2026-42482A stack-based buffer overflow in mangle_to_hex_lower() and m…9.8
- CVE-2026-42483A heap-based buffer overflow in the Kerberos hash parser in …9.8
- CVE-2026-42484A heap-based buffer overflow in hex_to_binary in the PKZIP h…9.8
- CVE-2026-42485AGL agl-service-can-low-level contains a stack buffer overfl…7.5
- CVE-2026-42487HVM guest I/O port accesses are subject to either emulation …7.9
- CVE-2026-42488Some shadow paging errors paths will switch the page-tables …8.1
- CVE-2026-42489[This CNA information record relates to multiple CVEs; the t…5.3
- CVE-2026-4249The throttling event handling mechanism in multiple WSO2 pro…8.6
- CVE-2026-42490[This CNA information record relates to multiple CVEs; the t…6.5
- CVE-2026-42492Xenstore, to have an up-to-date picture of the entire system…7.5
Are you affected by CVE-2026-42486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
