---
id: CVE-2026-88263
title: >-
  XikeStor Layer3 switches miss authentication for downloading configuration
  data
summary: >-
  XikeStor Layer3 switches miss authentication for downloading configuration
  data. Unauthenticated attacker may retrieve the configuration data containing
  network configurations and passwords to operate the affected product
  improperly or t…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: XikeStor
product: SKS8310-8X
affected:
  - SKS8310-8X < V1.04.B09
  - SKS8300-8T < V1.04.B09
  - SKS8300-12E2T2X < V1.04.B09
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88263'
references:
  - url: 'https://jvn.jp/en/jp/JVN45281119/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.xikestor.com/security-advisory/'
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T15:01:05.622997Z'
ingestedAt: '2026-09-16T07:51:48.494Z'
epss: 0.0056
epssPercentile: 0.45428
---

## Overview

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
