# CVE-2026-23556

## Summary

- **CVE ID:** CVE-2026-23556
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-281
- **Published:** Jul 9, 2026
- **Last Modified:** Jul 9, 2026

## Description

When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.

When the domain ID is eventually reused, the new domain can create fewer
nodes before beeing deemed to be over quota.

## Affected Products

- Xen — oxenstored (all)

## References

- [CNA](https://xenbits.xen.org/xsa/advisory-483.html)
- [CVE](http://www.openwall.com/lists/oss-security/2026/04/28/10)
- [CVE](http://xenbits.xen.org/xsa/advisory-483.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._