« Volver al listado

CVE-2026-9831

Estado: Pendiente de análisisMedia (6.3)—

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9831",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9831",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T13:52:52.575235Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "1c053176-eef3-4d6a-ae0b-24728c86587b",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "1c053176-eef3-4d6a-ae0b-24728c86587b",
      "affectedData": [
        {
          "vendor": "Extreme Networks",
          "product": "Extreme Platform ONE",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "25.10.0-104",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "25.10.0-104",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "SaaS (Cloud Hosted)"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-29T22:16:23.980",
  "references": [
    {
      "url": "https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2026-048-extremecloud-iq-cross-tenant-data-exposure-via/ba-p/121851",
      "source": "1c053176-eef3-4d6a-ae0b-24728c86587b"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "1c053176-eef3-4d6a-ae0b-24728c86587b",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        },
        {
          "lang": "en",
          "value": "CWE-488"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A race condition in the shared Extreme Platform\nONE IAM Gateway API-key authentication path could, under specific\nhigh-concurrency traffic conditions, intermittently allow requests\nauthenticated with an Extreme Platform ONE /IAM-issued API key to receive\nresponse data for another tenant. The issue was observed through ExtremeCloud\nIQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE\n/Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT\nauthentication were not affected."
    },
    {
      "lang": "es",
      "value": "Una condición de carrera en la ruta de autenticación de clave API compartida del IAM Gateway de Extreme Platform ONE podría, bajo condiciones específicas de tráfico de alta concurrencia, permitir intermitentemente que las solicitudes autenticadas con una clave API emitida por Extreme Platform ONE /IAM reciban datos de respuesta para otro inquilino. El problema se observó a través de los puntos finales de la API de ExtremeCloud IQ/XIQ y se validó tanto contra las rutas de la API de XIQ/XAPI como las de Extreme Platform ONE /Common Services. Los tokens nativos de XIQ y la autenticación estándar OAuth/Bearer JWT no se vieron afectados."
    }
  ],
  "lastModified": "2026-07-22T06:10:00.170",
  "sourceIdentifier": "1c053176-eef3-4d6a-ae0b-24728c86587b"
}