CVE-2025-26515: Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager non-federated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26515?
CVE-2025-26515 is rated as a critical severity vulnerability due to its potential to allow unauthorized password changes.
How do I fix CVE-2025-26515?
To remediate CVE-2025-26515, upgrade to NetApp StorageGRID versions 11.8.0.15 or 11.9.0.8 with Single Sign-on enabled.
Who is affected by CVE-2025-26515?
CVE-2025-26515 affects NetApp StorageGRID users running versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled.
What type of vulnerability is CVE-2025-26515?
CVE-2025-26515 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
What can an attacker achieve by exploiting CVE-2025-26515?
An attacker exploiting CVE-2025-26515 could change the password of any Grid without authentication.