CVE-2025-26517
BaseFortify
Publication date: 2025-09-19
Last updated on: 2025-09-23
Assigner: NetApp, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | storagegrid | to 11.8.0.15 (exc) |
| netapp | storagegrid | From 11.9.0 (inc) to 11.9.0.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects StorageGRID versions prior to 11.8.0.15 and 11.9.0.8, allowing an unauthorized authenticated attacker to escalate privileges. The attacker could discover Grid node names and IP addresses or modify Storage Grids.
How can this vulnerability impact me? :
The vulnerability could allow an attacker with some level of authentication to gain higher privileges, potentially exposing sensitive network information such as Grid node names and IP addresses, or enabling unauthorized modifications to Storage Grids, which could disrupt operations or compromise data integrity.