CVE-2026-88263

Summary

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.

Affected Software

VendorProductVersion RangeStatus
XikeStorSKS8310-8X0 < V1.04.B09affected
XikeStorSKS8300-8T0 < V1.04.B09affected
XikeStorSKS8300-12E2T2X0 < V1.04.B09affected

Weaknesses

  • CWE-306: Missing authentication for critical function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References