CVE-2025-26514: Netapp Storagegrid
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link.
Affected products
- Netapp Storagegrid: before 11.8.0.15 (fixed in 11.8.0.15); from 11.9.0, before 11.9.0.8 (fixed in 11.9.0.8)
Published 2025-09-19. Last modified 2026-06-17.