Xen XAPI flaw allows security bypass
A vulnerability in Xen XAPI (unpatched by xsa498.patch) lets an attacker bypass security policy enforcement.
ANSSI-CERT-FR published an advisory covering CVE-2026-42491, a vulnerability in Xen's XAPI toolstack that allows an attacker to circumvent security policy controls. The issue affects XAPI master instances that have not applied the xsa498.patch fix released by the Xen Project.
The vendor advisory (XSA-498) was published on 14 July 2026 with corresponding patches. Administrators running affected Xen XAPI deployments should apply the official patch referenced in the Xen security bulletin as soon as possible. No evidence of active exploitation is mentioned in the advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0884
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free