PT-2025-38589 · Netapp · Storagegrid

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-26514

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions StorageGRID versions prior to 11.8.0.15 StorageGRID versions prior to 11.9.0.8
Description StorageGRID (formerly StorageGRID Webscale) is susceptible to a Reflected Cross-Site Scripting issue. Successful exploitation could allow an attacker to view or modify configuration settings or add or modify user accounts, but requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted link.
Recommendations Update StorageGRID to version 11.8.0.15 or later. Update StorageGRID to version 11.9.0.8 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-26514

Affected Products

Storagegrid