CVE-2025-36255
Received Received - Intake

Privileged Role Escalation in IBM System Storage DS8A00 and DS8900F

Vulnerability report for CVE-2025-36255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm system_storage_ds8a00 From 10.1.3.0 (inc) to 10.11.35.0 (inc)
ibm ds8900f From 89.40.83.0 (inc) to 89.44.25.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-267 A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user to create another user with privileged roles in IBM System Storage DS8A00 and DS8900F products. This happens because the system improperly defines privileged actions, enabling unauthorized privilege escalation.

Impact Analysis

An attacker with access could create privileged accounts, potentially gaining control over storage systems. This may lead to data theft, unauthorized modifications, or disruption of storage services.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data, potentially breaching GDPR or HIPAA. Organizations may face penalties due to inadequate access controls.

Mitigation Strategies

Review user roles and permissions in IBM System Storage DS8A00 and DS8900F systems. Remove any unauthorized privileged users and ensure proper role definitions. Apply the latest firmware updates from IBM to address the improper privilege assignment issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart