CVE-2026-9831 PUBLISHED

ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition

Assigner: ExtremeNetworks
Reserved: 28.05.2026 Published: 29.05.2026 Updated: 29.05.2026

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 6.3

Product Status

Vendor Extreme Networks
Product Extreme Platform ONE
Versions Default: unaffected
  • affected from 0 to 25.10.0-104 (excl.)
  • Version 25.10.0-104 is unaffected

Credits

  • Sebastian Koller of Iteas IT Services GmbH (Austria) for responsible discovery and disclosure of this vulnerability. finder
  • Sebastian Koller of Iteas IT Services GmbH (Austria) for responsible coordination and providing detailed evidence supporting root cause identification. reporter

References

Problem Types

  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) CWE
  • CWE-488 Exposure of data element to wrong session CWE

Impacts

  • CAPEC-74: Manipulating State