Vulnerability Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager non-federated user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Storagegrid | < 11.8.0.15 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/NTAP-20250910-0002Vendor Advisory
FAQ
What is CVE-2025-26515?
CVE-2025-26515 is a vulnerability with a CVSS score of 7.5 (HIGH). StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful...
How severe is CVE-2025-26515?
CVE-2025-26515 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26515?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Storagegrid.