🛡️ CVE-2026-23561 on Alpine — xen
Description
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different roles, using Role
Based Access Control. For more details, see:
https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles
The pool-admin role is fully privileged. Notably, users with this role
can also SSH into the host as root.
The other administrator roles are pool-operator, vm-power-admin and
vm-admin, each of which are authorised to configure and manage various
aspects of the system.
Some settings are inadequately restricted, and can be set by a lower
privilege of administrator than expected.
- CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and
turn arbitrary files in dom0 into VDIs (virtual disks) and give said
disks to a VM they control. This is an arbitrary read and/or modify
of files in dom0.
- CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain
and mark a VM as a system domain. System domains are ignored and
left running during certain other host/pool operations, and may be
hidden from view in tooling.
- CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain
and mark a VM as the storage domain for a particular host storage
connection (PBD). Shutting down the VM can cause the PBD to be
erroneously marked as unplugged when it is not.
- CVE-2026-23562: Configuration of PCI passthrough is normally
restricted to the pool-admin role. However one API was missing this
check, allowing a vm-admin access to unintended host hardware.
- CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial
parameter, which should be restricted to the pool-admin role, as it
can allow arbitrary dom0 file write.
Distribution advisory
This page covers CVE-2026-23561 as tracked by Alpine, for the package xen. No fixed version has been recorded for this distribution yet.
How this vulnerability can be exploited
This issue can be reached with local access to the system, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.
Affected software
ALPINE-CVE-2026-23561 is recorded against 1 package.
- xen
Timeline and source
Published on 9 July 2026 and last revised on 14 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| xen | — | — |
References
Similar Threats
- Unknown ALPINE-CVE-2022-21123
- Unknown ALPINE-CVE-2022-21125
- Unknown ALPINE-CVE-2021-26401
- Unknown ALPINE-CVE-2021-28703
- Unknown ALPINE-CVE-2021-28706
More ALPINE CVE 2026 advisories
Browse all of ALPINE CVE 2026 in the advisory index.
- ALPINE-CVE-2026-23553
- ALPINE-CVE-2026-23554
- ALPINE-CVE-2026-23555
- ALPINE-CVE-2026-23556
- ALPINE-CVE-2026-23557
- ALPINE-CVE-2026-23558
- ALPINE-CVE-2026-23559
- ALPINE-CVE-2026-23560
- ALPINE-CVE-2026-23562
- ALPINE-CVE-2026-23631
- ALPINE-CVE-2026-23918
- ALPINE-CVE-2026-24031
- ALPINE-CVE-2026-24049
- ALPINE-CVE-2026-24072
- ALPINE-CVE-2026-24401
- ALPINE-CVE-2026-24515
Free Vulnerability Check
Is your site affected by ALPINE-CVE-2026-23561?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ALPINE-CVE-2026-23561 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.