CVE-2026-6445
Awaiting Analysis Awaiting Analysis - Queue

FlashArray Purity Information Disclosure Vulnerability

Vulnerability report for CVE-2026-6445, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: Pure Storage, Inc.

Description

A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-30
AI Q&A
2026-06-10
EPSS Evaluated
2026-06-28
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
purestorage flasharray_purity *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-939 The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

This vulnerability in FlashArray Purity involves insufficient filtering of certain data paths, which could expose sensitive information to an authenticated user with low privileges.

Exposure of sensitive information may lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require strict controls to prevent unauthorized access to personal and protected health information.

Therefore, organizations using affected versions of FlashArray Purity should consider this vulnerability as a risk to their compliance posture and take appropriate mitigation steps.

Executive Summary

This vulnerability exists in FlashArray Purity and involves insufficient filtering of certain data paths. As a result, an authenticated user with low privileges could potentially access sensitive information that should otherwise be restricted.

Impact Analysis

The impact of this vulnerability is that sensitive information could be exposed to users who have only low-level authentication privileges. This could lead to unauthorized disclosure of confidential data within the affected system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6445. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart