Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-23560

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
09/07/2026
Última modificación:
09/07/2026

Descripción

*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]<br /> XAPI can configure different users with different roles, using Role<br /> Based Access Control. For more details, see:<br /> <br /> https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles<br /> <br /> The pool-admin role is fully privileged. Notably, users with this role<br /> can also SSH into the host as root.<br /> <br /> The other administrator roles are pool-operator, vm-power-admin and<br /> vm-admin, each of which are authorised to configure and manage various<br /> aspects of the system.<br /> <br /> Some settings are inadequately restricted, and can be set by a lower<br /> privilege of administrator than expected.<br /> <br /> * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and<br /> turn arbitrary files in dom0 into VDIs (virtual disks) and give said<br /> disks to a VM they control. This is an arbitrary read and/or modify<br /> of files in dom0.<br /> <br /> * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain<br /> and mark a VM as a system domain. System domains are ignored and<br /> left running during certain other host/pool operations, and may be<br /> hidden from view in tooling.<br /> <br /> * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain<br /> and mark a VM as the storage domain for a particular host storage<br /> connection (PBD). Shutting down the VM can cause the PBD to be<br /> erroneously marked as unplugged when it is not.<br /> <br /> * CVE-2026-23562: Configuration of PCI passthrough is normally<br /> restricted to the pool-admin role. However one API was missing this<br /> check, allowing a vm-admin access to unintended host hardware.<br /> <br /> * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial<br /> parameter, which should be restricted to the pool-admin role, as it<br /> can allow arbitrary dom0 file write.

Referencias a soluciones, herramientas e información