CVE-2026-19180

Max CVSS: 9.4
Published: August 14, 2026

Xona Systems Security Advisory

XSA-2026-002

Security Vulnerability in Xona SRA Manager — Manager-Connected Deployments

CVE

CVE-2026-19180

Affected versions

v5.3.0 and later (prior to fixed version — TBD)

Fixed version

Expected in v5.6.0

Severity

Critical (CVSS v4.0: 9.4 / CVSS v3.1: 9.0)

Deployments affected

Manager-connected deployments only

Published

8/14/26

 
This vulnerability scores 9.4 Critical as a standalone finding. The currently demonstrated exploitation path requires a prerequisite condition addressed by the v5.5.4 update (XSA-2026-001). Customers who have applied v5.5.4 are not currently exposed to the known exploitation chain. The standalone Critical score reflects the severity of this vulnerability to any caller within the Gateway-to-Manager network. The currently known path to that network from a web session is addressed by v5.5.4; the underlying vulnerability in the Manager service remains until a further fix is released.

Summary

A security vulnerability in the Xona SRA Manager could allow an attacker who has obtained access to the Gateway-to-Manager network to access and modify sensitive Manager data without authentication. Xona has confirmed this issue and a fix is under development.

The currently known exploitation path for this vulnerability is addressed by upgrading to v5.5.4. Customers who have applied v5.5.4 are not exposed to the known exploitation chain. The underlying Manager vulnerability will be addressed in a further update.

Xona has no evidence that this vulnerability has been exploited in the wild.

Who is affected

Customers running Xona SRA v5.3.0 or later with a Manager connected to one or more Gateways. Standalone Gateway deployments without a Manager are not affected by this vulnerability. Customers on versions prior to v5.3.0 are not affected by this specific vulnerability but should review XSA-2026-001.

Customers who have not yet applied v5.5.4 are exposed to a combined exploitation chain scoring 6.3 Medium (CVSS v4.0) / 8.8 High (CVSS v3.1) via XSA-2026-001.

What to do

Upgrade to Xona SRA v5.5.4 immediately. This update closes the currently known access path to this vulnerability. A further update addressing the underlying Manager vulnerability is planned for Xona SRA v5.6.0. Customers will be notified when it is available.

The following measures should be applied in addition to upgrading:

  • Apply best practice security procedures appropriate for your environment, including but not limited to:
    • Enforcing principle of least privilege via RBAC inside the Xona platform, and with firewalls and segmentation at the network layer
    • Using session recording for all sessions and live monitoring when appropriate
    • Ensuring connection approval workflows are used
  • Review strong password policies (which are enabled by default in the Xona platform) for all user accounts, and use MFA when available
  • Verify your Manager administrator account configuration as part of applying v5.5.4, confirming that the account inventory reflects only expected accounts

Upgrading to v5.5.4 closes the currently known exploitation path but does not fully remediate this vulnerability. A further security update is required. Customers will be notified when it is available.

Further information

Security teams, researchers, and customers with questions about this vulnerability should contact Xona Support at support@xonasystems.com