CVE Vulnerabilities

CVE-2025-26517

Incorrect Privilege Assignment

Published: Sep 19, 2025 | Modified: Sep 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker to discover Grid node names and IP addresses or modify Storage Grades.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Storagegrid Netapp * 11.8.0.15 (excluding)
Storagegrid Netapp 11.9.0 (including) 11.9.0.8 (excluding)

Potential Mitigations

References