Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-23556— oxenstored keeps quota related use counts across domain destruction

Quick assessment

Affected
Xen oxenstored
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xen oxenstored是Xen组织的一款存储守护进程。 Xen oxenstored存在权限许可和访问控制问题漏洞,该漏洞源于在销毁域时节点数据已清理但使用计数泄露,当域ID被重新使用时,新域可创建的节点数少于正常配额,导致权限许可和访问控制问题。

AI Predicted 5.9 Difficulty: Moderate EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Xen oxenstored all affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-23556

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
oxenstored keeps quota related use counts across domain destruction
Source: CVE Program / CVE List V5
Vulnerability Description
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
权限预留不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Xen oxenstored 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xen oxenstored是Xen组织的一款存储守护进程。 Xen oxenstored存在权限许可和访问控制问题漏洞,该漏洞源于在销毁域时节点数据已清理但使用计数泄露,当域ID被重新使用时,新域可创建的节点数少于正常配额,导致权限许可和访问控制问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Xen oxenstored all -

II. Public POCs for CVE-2026-23556

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23556

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-23556 (1)

Same Patch Batch · Xen · 2026-07-09 · 11 CVEs total

CVE-2026-42486 Multiple RBAC issues in XAPI
CVE-2026-23562 Multiple RBAC issues in XAPI
CVE-2026-23560 Multiple RBAC issues in XAPI
CVE-2026-23561 Multiple RBAC issues in XAPI
CVE-2026-23559 Multiple RBAC issues in XAPI
CVE-2025-58146 XAPI UTF-8 string handling
CVE-2025-58151 varstored: TOCTOU issues with mapped guest memory
CVE-2025-27464 WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-27462 WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-27463 WinPVDrivers: Excessive permissions on user-exposed devices

IV. Related Vulnerabilities

V. Comments for CVE-2026-23556

No comments yet


Leave a comment