CVE Feed

    Dashboard / CVE / CVE-2026-0689

    CVE-2026-0689

    In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying credential values in the HTTP response, enabling an authorized administrator to recover stored secrets that may exceed their intended access. We would like to thank the Lockheed Martin Red Team for responsibly reporting this issue and working with us through coordinated disclosure.

    Published:Mar 2, 2026
    Last Modified:Jun 5, 2026
    EPS:Mar 2, 2026
    EPSS Score:0.00053
    CVSS Score:4.9

    Affected Products

    Vendor
    Extremenetworks
    Product
    Extremecloud Iq - Site Engine
    Vendor
    Extremenetworks
    Product
    Extremecloud Iq Site Engine

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High