Xen disclosed XSA-489 covering five role-based access control flaws in XAPI, tracked as CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486. The vulnerabilities affect deployments where RBAC is enabled and roles such as vm-admin, vm-power-admin, or pool-operator are assigned, allowing those lower-privileged administrators to perform actions intended only for pool-admin. Xen said the impact includes privilege escalation and, in some cases, arbitrary dom0 file read, modification, or write.
The advisory states that all versions of XAPI are vulnerable under the affected RBAC conditions. Xen urged administrators to disable RBAC subjects assigned to vm-admin, vm-power-admin, or pool-operator until patches are applied. Fixes have been merged and backported in XAPI and are available in releases v26.12.0 and v26.1.11. Xen also noted the issues were publicly disclosed without embargo and said maintainers validated five real vulnerabilities out of 89 claims submitted by the researcher.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A version 2 advisory was circulated on oss-sec with additional detail on the five validated RBAC vulnerabilities, including that some flaws could enable arbitrary dom0 file read, modification, or write. The notice reiterated affected roles, mitigation guidance, and fixed versions.
Xen published Security Advisory XSA-489 covering CVE-2026-23559, CVE-2026-23560, CVE-2026-23561, CVE-2026-23562, and CVE-2026-42486. The advisory says all XAPI versions are affected when RBAC is enabled and certain lower-privileged roles are assigned, and recommends disabling vm-admin, vm-power-admin, or pool-operator RBAC subjects until patches are applied.
Fixes for the validated RBAC vulnerabilities were merged and backported in XAPI. The remediations were made available in XAPI releases v26.12.0 and v26.1.11.
A researcher publicly disclosed a large set of claimed RBAC issues in Xen XAPI without embargo. XAPI maintainers later said they validated 5 real vulnerabilities out of 89 claims submitted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcexenbits.xen.org
Open sourcegna.moksha.dk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.