CVE-2025-26517: Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker to discover Grid node names and IP addresses or modify Storage Grades.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26517?
CVE-2025-26517 is considered a privilege escalation vulnerability that could allow unauthorized access to sensitive information.
How do I fix CVE-2025-26517?
To mitigate CVE-2025-26517, upgrade to NetApp StorageGRID versions 11.8.0.15 or 11.9.0.8 or later.
Who is affected by CVE-2025-26517?
CVE-2025-26517 affects users of NetApp StorageGRID versions prior to 11.8.0.15 and 11.9.0.8.
What can an attacker achieve by exploiting CVE-2025-26517?
An attacker exploiting CVE-2025-26517 can discover Grid node names and IP addresses or modify StorageGRID settings.
When was CVE-2025-26517 disclosed?
CVE-2025-26517 was disclosed as part of a NetApp security advisory on September 10, 2025.