Server-Side Request Forgery Vulnerability in StorageGRID by NetApp
CVE-2025-26515
What is CVE-2025-26515?
NetApp's StorageGRID product, particularly in versions prior to 11.8.0.15 and 11.9.0.8, is vulnerable to a Server-Side Request Forgery (SSRF) attack when Single Sign-on (SSO) is not enabled. This security flaw can be exploited by an unauthenticated attacker, allowing them to change the passwords of any non-federated user, including Grid Managers and Tenant Managers, potentially leading to unauthorized access and significant security risks. Ensuring proper version updates and enabling SSO can mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
StorageGRID 0 < 11.8.0.15
StorageGRID 0 < 11.9.0.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
