CVE-2025-26516
BaseFortify
Publication date: 2025-09-19
Last updated on: 2025-09-23
Assigner: NetApp, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | storagegrid | to 11.8.0.15 (exc) |
| netapp | storagegrid | From 11.9.0 (inc) to 11.9.0.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-405 | The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric." |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The impact of this vulnerability is a Denial of Service on the Admin node of StorageGRID, which means that the administrative functions could become unavailable or unresponsive. This could prevent administrators from managing or configuring the system, potentially leading to operational disruptions.
Can you explain this vulnerability to me?
This vulnerability affects StorageGRID versions prior to 11.8.0.15 and 11.9.0.8, allowing an unauthenticated attacker to cause a Denial of Service (DoS) on the Admin node. Essentially, an attacker can disrupt the normal operation of the system's administrative interface without needing any credentials.