CVE-2026-88263
Received
Received - Intake
Unauthenticated Configuration Data Exposure in XikeStor Layer3 Switches
Vulnerability report for CVE-2026-88263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: JPCERT/CC
Description
Description
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| xikestor | layer3_switches | to 1.04.b09 (exc) |
| xikestor | sks8310-8x | to 1.04.b09 (exc) |
| xikestor | sks8300-8t | to 1.04.b09 (exc) |
| xikestor | sks8300-12e2t2x | to 1.04.b09 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |