StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without
Single Sign-on enabled are susceptible to a Server-Side Request Forgery
(SSRF) vulnerability. Successful exploit could allow an unauthenticated
attacker to change the password of any Grid Manager or Tenant Manager
non-federated user.
References
| Link | Resource |
|---|---|
| https://security.netapp.com/advisory/NTAP-20250910-0002 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-19 19:15
Updated : 2025-09-23 14:31
NVD link : CVE-2025-26515
Mitre link : CVE-2025-26515
CVE.ORG link : CVE-2025-26515
JSON object : View
Products Affected
netapp
- storagegrid
CWE
CWE-918
Server-Side Request Forgery (SSRF)
