PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9831 Extreme Networks CVE debrief

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE/Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected.

Vendor
Extreme Networks
Product
Extreme Platform ONE
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-29
Original CVE updated
2026-07-22
Advisory published
2026-05-29
Advisory updated
2026-07-22

Who should care

Organizations operating multi-tenant ExtremeCloud IQ or Extreme Platform ONE deployments with API-key authenticated integrations, particularly those with high-volume concurrent API traffic. Security teams responsible for tenant isolation in cloud-managed networking platforms.

Technical summary

The vulnerability exists in the shared IAM Gateway component used for API-key authentication across Extreme Platform ONE and ExtremeCloud IQ services. Under high-concurrency request conditions, a race condition in the authentication path can cause request context mixing between tenants, resulting in authenticated users receiving data belonging to other tenants. The issue is specific to API-key authentication flows; OAuth/Bearer JWT and XIQ-native token authentication are unaffected. The CVSS vector indicates network attack vector, high attack complexity, low privileges required, no user interaction, changed scope, and high confidentiality impact with no integrity or availability impact.

Defensive priority

HIGH

Recommended defensive actions

  • Review Extreme Networks security advisory SA-2026-048 for patch availability and deployment guidance
  • Audit API key usage in ExtremeCloud IQ and Extreme Platform ONE environments to identify high-concurrency API consumers
  • Monitor for anomalous cross-tenant data access patterns in API gateway logs
  • Prioritize patching for multi-tenant deployments with high-volume API-key authenticated traffic
  • Consider implementing request-level tenant isolation validation as compensating control until patch deployment

Evidence notes

CVE published 2026-05-29. Vendor advisory confirms cross-tenant data exposure via race condition in API-key authentication path. CVSS 6.3 (Medium). Not in KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9831 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9831

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9831 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9831

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2026-048-extremecloud-iq-cross-tenant-data-exposure-via/ba-p/121851

    1c053176-eef3-4d6a-ae0b-24728c86587b

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.