🛡️ CVE-2026-23562 on Alpine — xen

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]

XAPI can configure different users with different roles, using Role

Based Access Control. For more details, see:

https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles

The pool-admin role is fully privileged. Notably, users with this role

can also SSH into the host as root.

The other administrator roles are pool-operator, vm-power-admin and

vm-admin, each of which are authorised to configure and manage various

aspects of the system.

Some settings are inadequately restricted, and can be set by a lower

privilege of administrator than expected.

  • CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and

turn arbitrary files in dom0 into VDIs (virtual disks) and give said

disks to a VM they control. This is an arbitrary read and/or modify

of files in dom0.

  • CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain

and mark a VM as a system domain. System domains are ignored and

left running during certain other host/pool operations, and may be

hidden from view in tooling.

  • CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain

and mark a VM as the storage domain for a particular host storage

connection (PBD). Shutting down the VM can cause the PBD to be

erroneously marked as unplugged when it is not.

  • CVE-2026-23562: Configuration of PCI passthrough is normally

restricted to the pool-admin role. However one API was missing this

check, allowing a vm-admin access to unintended host hardware.

  • CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial

parameter, which should be restricted to the pool-admin role, as it

can allow arbitrary dom0 file write.

Distribution advisory

This page covers CVE-2026-23562 as tracked by Alpine, for the package xen. No fixed version has been recorded for this distribution yet.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Affected software

ALPINE-CVE-2026-23562 is recorded against 1 package.

  • xen

Timeline and source

Published on 9 July 2026 and last revised on 14 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

security.alpinelinux.org (Advisory)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-09
Updated 2026-08-11
Modified 2026-07-14
Fix URL N/A

Affected Packages

Software From version Fixed in
xen

Free Vulnerability Check

Is your site affected by ALPINE-CVE-2026-23562?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ALPINE-CVE-2026-23562 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.