In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.