# Xen XAPI flaw allows security bypass

Published: 2026-07-15 · Severity: medium
Canonical: https://vorant.io/reports/15ac0ed1-59d9-590e-bcf3-83e877898e35/xen-xapi-flaw-allows-security-bypass

> A vulnerability in Xen XAPI (unpatched by xsa498.patch) lets an attacker bypass security policy enforcement.

ANSSI-CERT-FR published an advisory covering CVE-2026-42491, a vulnerability in Xen's XAPI toolstack that allows an attacker to circumvent security policy controls. The issue affects XAPI master instances that have not applied the xsa498.patch fix released by the Xen Project.

The vendor advisory (XSA-498) was published on 14 July 2026 with corresponding patches. Administrators running affected Xen XAPI deployments should apply the official patch referenced in the Xen security bulletin as soon as possible. No evidence of active exploitation is mentioned in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42491

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0884

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/15ac0ed1-59d9-590e-bcf3-83e877898e35/xen-xapi-flaw-allows-security-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
