Server-Side Request Forgery Vulnerability in StorageGRID by NetApp
CVE-2025-26515

7.5HIGH

Key Information:

Vendor

Netapp

Vendor
CVE Published:
19 September 2025

What is CVE-2025-26515?

NetApp's StorageGRID product, particularly in versions prior to 11.8.0.15 and 11.9.0.8, is vulnerable to a Server-Side Request Forgery (SSRF) attack when Single Sign-on (SSO) is not enabled. This security flaw can be exploited by an unauthenticated attacker, allowing them to change the passwords of any non-federated user, including Grid Managers and Tenant Managers, potentially leading to unauthorized access and significant security risks. Ensuring proper version updates and enabling SSO can mitigate this risk.

Affected Version(s)

StorageGRID 0 < 11.8.0.15

StorageGRID 0 < 11.9.0.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26515 : Server-Side Request Forgery Vulnerability in StorageGRID by NetApp