CVE-2025-26514

Published Sep 19, 2025

Last updated 6 months ago

Overview

Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.
Source
security-alert@netapp.com
NVD status
Analyzed
Products
storagegrid

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.4
Impact score
4.7
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Severity
MEDIUM

Weaknesses

security-alert@netapp.com
CWE-79

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.