Security Advisory

CVE-2026-50741

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-26 01:11:14
Last updated 2026-06-26 12:27:43
Assigner hackerone
CVSS score 8.8
State PUBLISHED

Description

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.