CVE-2026-88263 Details
Description
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
A vulnerability exists in XikeStor Layer3 switches, specifically in the SKS8310-8X, SKS8300-8T, and SKS8300-12E2T2X models, all versions prior to V1.04.B09. The issue arises from a lack of authentication for downloading configuration files, which can be accessed by unauthenticated attackers. These files may contain sensitive information such as network configurations and passwords, potentially allowing improper operation of the affected device or exploitation of the device as a jump host.
Users are advised to upgrade to the latest version of the firmware, which is available through the XikeStor Download Center. The vulnerability has been fixed in the firmware released on April 28, 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN45281119/ | [email protected] | AdvisoryRemedy |
| https://www.xikestor.com/security-advisory/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| XikeStor SKS8310-8X | < V1.04.B09 |
CPE
Remediation
| |
| XikeStor SKS8300-8T | < V1.04.B09 |
CPE
Remediation
| |
| XikeStor SKS8300-12E2T2X | < V1.04.B09 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion