cbcvebase.
CVE-2025-26514
published 2025-09-19

CVE-2025-26514: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability…

PriorityP432medium6.4CVSS 3.1
AVNACHPRNUIRSUCLIHAL
EPSS
0.22%
13.0th percentile
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.

Affected

3 ranges
VendorProductVersion rangeFixed in
netappstoragegrid< 11.9.0.811.9.0.8
netappstoragegrid< 11.8.0.1511.8.0.15
netappstoragegrid>= 11.9.0 < 11.9.0.811.9.0.8
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.