CVE-2026-13460: IBM Storage Scale

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.

Affected products

  • IBM Storage Scale: from 5.2.3.0, before 5.2.3.9 (fixed in 5.2.3.9); from 6.0.0.0, before 6.0.1.1 (fixed in 6.0.1.1)

Published 2026-08-13. Last modified 2026-08-17.