moksha-2026-0079
MEDIUM CVSS 4.1 moksha
Description
A pool-operator in XAPI-based hypervisors (XenServer, XCP-ng) can bypass network locality checks by setting assume_network_is_shared=true in Network.other_config. The key is checked at xapi_network_attach_helpers.ml:132-133. When set, XAPI treats the network as shared across all hosts regardless of actual PIF connectivity, allowing VMs to start on hosts without network infrastructure. This causes VIF attachment failures or silent connectivity loss. The field has no map_keys_roles entries for infrastructure keys.
Timeline
- Published
- 2026-04-24 06:00 UTC
- Last Modified
- 2026-04-24
CVSS Details
CVSS details not available.
Affected Products
- Cloud Software Group XenServer
- Vates XCP-ng
References
Linked Vulnerabilities
No linked vulnerabilities found.
{
"containers": {
"cna": {
"affected": [
{
"product": "XenServer",
"vendor": "Cloud Software Group",
"versions": [
{
"status": "affected",
"version": "all",
"versionType": "custom"
}
]
},
{
"product": "XCP-ng",
"vendor": "Vates",
"versions": [
{
"status": "affected",
"version": "all",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jakob Wolffhechel, Moksha"
}
],
"descriptions": [
{
"lang": "en",
"value": "A pool-operator in XAPI-based hypervisors (XenServer, XCP-ng) can bypass network locality checks by setting assume_network_is_shared=true in Network.other_config. The key is checked at xapi_network_attach_helpers.ml:132-133. When set, XAPI treats the network as shared across all hosts regardless of actual PIF connectivity, allowing VMs to start on hosts without network infrastructure. This causes VIF attachment failures or silent connectivity loss. The field has no map_keys_roles entries for infrastructure keys."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"format": "CVSS"
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-24T06:00:00Z",
"orgId": "moksha.dk",
"shortName": "Moksha"
},
"references": [
{
"url": "https://cna.moksha.dk/MOKSHA-2026-0079"
}
],
"title": "Network Sharing Bypass via Network.other_config assume_network_is_shared"
}
},
"cveMetadata": {
"alternateIds": [
"GCVE-117-2026-0079"
],
"assignerOrgId": "moksha.dk",
"cveId": "MOKSHA-2026-0079",
"datePublished": "2026-04-24T06:00:00Z",
"state": "PUBLISHED",
"x_moksha_note": "Self-issued advisory. MOKSHA-2026-NNNN is not a MITRE CVE ID. Schema follows CVE JSON 5.1 for tooling compatibility. alternateIds contains GCVE cross-references (GNA #117) and will also carry MITRE CVE IDs if assigned."
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1",
"vulnerability-lookup:id": "moksha-2026-0079",
"vulnerability-lookup:score": 1777010400.0
}