ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
Summary
| CVE | CVE-2026-9831 |
|---|---|
| State | PUBLISHED |
| Assigner | ExtremeNetworks |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-29 22:16:23 UTC |
| Updated | 2026-06-01 18:02:29 UTC |
| Description | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected. |
Risk And Classification
Primary CVSS: v3.1 6.3 MEDIUM from 1c053176-eef3-4d6a-ae0b-24728c86587b
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS: 0.000500000 probability, percentile 0.158450000 (date 2026-06-01)
Problem Types: CWE-362 | CWE-488 | CWE-362 CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) | CWE-488 CWE-488 Exposure of data element to wrong session
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 1c053176-eef3-4d6a-ae0b-24728c86587b | Secondary | 6.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Extreme Networks | Extreme Platform ONE | affected 25.10.0-104 custom | SaaS (Cloud Hosted) |
| CNA | Extreme Networks | Extreme Platform ONE | unaffected 25.10.0-104 custom | SaaS (Cloud Hosted) |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| community.extremenetworks.com/t5/security-advisories-formerly/sa-2026-048-extremecloud-iq-c... | 1c053176-eef3-4d6a-ae0b-24728c86587b | community.extremenetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sebastian Koller of Iteas IT Services GmbH (Austria) for responsible discovery and disclosure of this vulnerability. (en)
CNA: Sebastian Koller of Iteas IT Services GmbH (Austria) for responsible coordination and providing detailed evidence supporting root cause identification. (en)
There are currently no legacy QID mappings associated with this CVE.