CVE-2026-42486
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
10/07/2026
Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]<br />
XAPI can configure different users with different roles, using Role<br />
Based Access Control. For more details, see:<br />
<br />
https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles<br />
<br />
The pool-admin role is fully privileged. Notably, users with this role<br />
can also SSH into the host as root.<br />
<br />
The other administrator roles are pool-operator, vm-power-admin and<br />
vm-admin, each of which are authorised to configure and manage various<br />
aspects of the system.<br />
<br />
Some settings are inadequately restricted, and can be set by a lower<br />
privilege of administrator than expected.<br />
<br />
* CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and<br />
turn arbitrary files in dom0 into VDIs (virtual disks) and give said<br />
disks to a VM they control. This is an arbitrary read and/or modify<br />
of files in dom0.<br />
<br />
* CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain<br />
and mark a VM as a system domain. System domains are ignored and<br />
left running during certain other host/pool operations, and may be<br />
hidden from view in tooling.<br />
<br />
* CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain<br />
and mark a VM as the storage domain for a particular host storage<br />
connection (PBD). Shutting down the VM can cause the PBD to be<br />
erroneously marked as unplugged when it is not.<br />
<br />
* CVE-2026-23562: Configuration of PCI passthrough is normally<br />
restricted to the pool-admin role. However one API was missing this<br />
check, allowing a vm-admin access to unintended host hardware.<br />
<br />
* CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial<br />
parameter, which should be restricted to the pool-admin role, as it<br />
can allow arbitrary dom0 file write.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



