StorageGRID (formerly
StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without
Single Sign-on enabled are susceptible to a Server-Side Request Forgery
(SSRF) vulnerability. Successful exploit could allow an unauthenticated
attacker to change the password of any Grid Manager or Tenant Manager
non-federated user.
References
| Link | Resource |
|---|---|
| https://security.netapp.com/advisory/NTAP-20250910-0002 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Sep 2025, 14:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* | |
| First Time |
Netapp storagegrid
Netapp |
|
| References | () https://security.netapp.com/advisory/NTAP-20250910-0002 - Vendor Advisory |
19 Sep 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-19 19:15
Updated : 2025-09-23 14:31
NVD link : CVE-2025-26515
Mitre link : CVE-2025-26515
CVE.ORG link : CVE-2025-26515
JSON object : View
Products Affected
netapp
- storagegrid
CWE
CWE-918
Server-Side Request Forgery (SSRF)
