CVE-2026-13460: The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
Other sources
IBM Storage Scale GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Storage Scale Management GUIto a version that resolves this vulnerability.Fixed in 5.2.3.9 - Upgrade
Upgrade
IBM Storage Scale Management GUIto a version that resolves this vulnerability.Fixed in 6.0.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13460?
The severity of CVE-2026-13460 is rated high with a score of 7.5.
How do I fix CVE-2026-13460?
To fix CVE-2026-13460, upgrade to IBM Storage Scale version 5.2.3.9 or higher, or 6.0.1.1 or higher.
What software is affected by CVE-2026-13460?
CVE-2026-13460 affects IBM Storage Scale versions 5.2.3.0 to 5.2.3.8 and 6.0.0.0 to 6.0.1.0.
What kind of vulnerability is CVE-2026-13460?
CVE-2026-13460 is a vulnerability that involves a hardcoded token used for cluster communication and API authentication.
Is the IBM Storage Scale Management GUI impacted by CVE-2026-13460?
Yes, the IBM Storage Scale Management GUI is impacted by CVE-2026-13460 due to the hardcoded token issue.