Hardcoded Token Vulnerability in IBM Storage Scale GUI
CVE-2026-13460

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
13 August 2026

What is CVE-2026-13460?

The IBM Storage Scale GUI versions 5.2.3.0 to 5.2.3.8 and 6.0.0.0 to 6.0.1.0 are vulnerable due to a hardcoded token present in the source code. This token facilitates inter-node cluster communication and is utilized for REST API authentication, posing a security risk. Malicious actors could exploit this vulnerability to gain unauthorized access to sensitive functionalities, compromising the system's integrity. Users are urged to update their installations to mitigate potential threats.

Affected Version(s)

Storage Scale 5.2.3.0 <= 5.2.3.8

Storage Scale 6.0.0.0 <= 6.0.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.