Extreme Networks ExtremeCloud IQ - Site Engine NAC Admin Credential Exposure Vulnerability

Vulnerability

A vulnerability exists in the NAC administration interface of ExtremeCloud IQ - Site Engine (XIQ-SE) versions prior to 26.2.10. This vulnerability allows authenticated NAC administrators to access masked sensitive information, such as credential values, from HTTP responses. Although the user interface redacts these credentials, the application inadvertently reveals the actual values in the response, enabling administrators to retrieve stored secrets that may exceed their authorized access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive credentials, allowing an administrator to gain access to information or resources beyond their intended permissions.

Remediation

Users can upgrade to ExtremeCloud IQ - Site Engine version 26.2.10 or later to address this vulnerability.

Added: Mar 2, 2026, 4:23 PM
Updated: Mar 2, 2026, 9:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.