Summary
A security update has been released for a third-party data transfer library and command line utility to address multiple defects. The Ubuntu vulnerabilities affect connection reuse decisions, proxy authentication state retained between requests, cookie domain validation, credential selection from a local credentials file, and server verification during encrypted transport and secure shell sessions. A remote or machine-in-the-middle attacker could potentially obtain authentication credentials, set cookies that are transmitted to unrelated third-party domains, cause an unintended transport security configuration to be used, impersonate a trusted server, or trigger memory corruption resulting in a denial of service. The vendor has evaluated these issues against affected offerings and resolved them in the referenced maintenance release.
The following CVEs have been addressed:
CVE-2026-8286, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, and CVE-2026-9547.
Products not listed in the Impact Details section have not been evaluated. Furthermore, products that have exceeded any software maintenance time periods are also not evaluated and will not be published. Please consult End of Sale and End of Service Life - Extreme Networks for the EOL notices related to the product under question.
Products Potentially Affected
None
Impact Details
|
OS/Product
|
Exposure
|
|
ExtremeAnalytics for Site Engine
|
Yes
|
|
ExtremeCloud IQ - Site Engine (XIQ-SE)
|
Yes
|
|
ExtremeControl for Site Engine
|
Yes
|
Repair Recommendations
ExtremeAnalytics for Site Engine:
- Fixed in 26.8.10 or later.
ExtremeCloud IQ - Site Engine (XIQ-SE):
- Fixed in 26.8.10 or later.
ExtremeControl for Site Engine:
- Fixed in 26.8.10 or later.
Please see the full Security Advisory here for more details and future updates.