StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without
Single Sign-on enabled are susceptible to a Server-Side Request Forgery
(SSRF) vulnerability. Successful exploit could allow an unauthenticated
attacker to change the password of any Grid Manager or Tenant Manager
non-federated user.
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/NTAP-20250910-0002 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Sep 2025, 14:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* | |
First Time |
Netapp
Netapp storagegrid |
|
References | () https://security.netapp.com/advisory/NTAP-20250910-0002 - Vendor Advisory |
19 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-19 19:15
Updated : 2025-09-23 14:31
NVD link : CVE-2025-26515
Mitre link : CVE-2025-26515
CVE.ORG link : CVE-2025-26515
JSON object : View
Products Affected
netapp
- storagegrid
CWE
CWE-918
Server-Side Request Forgery (SSRF)