ONE IAM Gateway API-key authentication path could, under specific
high-concurrency traffic conditions, intermittently allow requests
authenticated with an Extreme Platform ONE /IAM-issued API key to receive
response data for another tenant. The issue was observed through ExtremeCloud
IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE
/Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT
authentication were not affected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Extreme Networks
Extreme Networks extreme Platform One |
|
| Vendors & Products |
Extreme Networks
Extreme Networks extreme Platform One |
Fri, 29 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extreme Platform ONE /Common Services API paths. XIQ-native tokens and standard OAuth/Bearer JWT authentication were not affected. | |
| Title | ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition | |
| Weaknesses | CWE-362 CWE-488 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ExtremeNetworks
Published:
Updated: 2026-06-01T13:53:05.140Z
Reserved: 2026-05-28T12:21:45.520Z
Link: CVE-2026-9831
Updated: 2026-06-01T13:53:00.145Z
Status : Awaiting Analysis
Published: 2026-05-29T22:16:23.980
Modified: 2026-06-01T18:02:29.343
Link: CVE-2026-9831
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:17:54Z