Privilege Escalation Vulnerability in NetApp StorageGRID
CVE-2025-26517

5.4MEDIUM

Key Information:

Vendor

Netapp

Vendor
CVE Published:
19 September 2025

What is CVE-2025-26517?

NetApp StorageGRID versions before 11.8.0.15 and 11.9.0.8 are vulnerable to a privilege escalation issue. An authenticated attacker with unauthorized access may exploit this vulnerability to gain insights into Grid node names and IP addresses, as well as modify Storage Grades. Prompt updates are recommended to enhance security.

Affected Version(s)

StorageGRID 0 < 11.8.0.15

StorageGRID 0 < 11.9.0.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26517 : Privilege Escalation Vulnerability in NetApp StorageGRID