Description
A race condition in the shared Extreme Platform
ONE IAM Gateway API-key authentication path could, under specific
high-concurrency traffic conditions, intermittently allow requests
authenticated with an Extreme Platform ONE /IAM-issued API key to receive
response data for another tenant. The issue was observed through ExtremeCloud
IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE
/Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT
authentication were not affected.
Published: 2026-05-29
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 30 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Extreme Networks
Extreme Networks extreme Platform One
Vendors & Products Extreme Networks
Extreme Networks extreme Platform One

Fri, 29 May 2026 21:45:00 +0000

Type Values Removed Values Added
Description A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected.
Title ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
Weaknesses CWE-362
CWE-488
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Extreme Networks Extreme Platform One
cve-icon MITRE

Status: PUBLISHED

Assigner: ExtremeNetworks

Published:

Updated: 2026-06-01T13:53:05.140Z

Reserved: 2026-05-28T12:21:45.520Z

Link: CVE-2026-9831

cve-icon Vulnrichment

Updated: 2026-06-01T13:53:00.145Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-29T22:16:23.980

Modified: 2026-06-01T18:02:29.343

Link: CVE-2026-9831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T21:17:54Z

Weaknesses