🔐 CVE Alert

CVE-2026-8169

UNKNOWN 0.0

ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges. Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.

CWE CWE-338
Vendor extreme networks
Product switch engine (exos)
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for extreme networks switch engine (exos)

Be the first to know when new unknown vulnerabilities affecting extreme networks switch engine (exos) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Extreme Networks / Switch Engine (EXOS)
0 < 31.7.4 32.0.0 < 32.7.4.15 33.0.0 < 33.1.100 33.2.0 < 33.7.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
extremenetworks.com: https://www.extremenetworks.com/support/policies/product-security

Credits

Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.