StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.
History

Tue, 23 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*

Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp storagegrid
Vendors & Products Netapp
Netapp storagegrid

Fri, 19 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.
Title CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published:

Updated: 2025-09-19T18:49:58.274Z

Reserved: 2025-02-11T21:58:04.395Z

Link: CVE-2025-26514

cve-icon Vulnrichment

Updated: 2025-09-19T18:49:50.581Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-19T19:15:38.367

Modified: 2025-09-23T14:32:00.057

Link: CVE-2025-26514

cve-icon Redhat

No data.