SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-62429

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability allows unauthorized access to vNUMA configuration data of a guest even after the domain destruction process has begun, due to a lack of synchronization between the cleanup of this data and its retrieval by the device model. This could lead to potential information disclosure or manipulation of guest configurations. Organizations utilizing virtualization technologies that rely on vNUMA configurations should prioritize addressing this issue to mitigate risks associated with guest domain management.

CVE
CVE-2026-62429
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchronized with its retrieval by a device model controlling the guest.