CVE-2025-26515
7.5NetApp · StorageGRID
A Server-Side Request Forgery vulnerability in NetApp StorageGRID allows unauthenticated attackers to reset passwords for non-federated Grid or Tenant Manager users.
Executive summary
A critical Server-Side Request Forgery vulnerability in NetApp StorageGRID allows unauthenticated attackers to perform unauthorized account password resets.
Vulnerability
The application is susceptible to a Server-Side Request Forgery (CWE-918) when Single Sign-on is not enabled. This flaw allows an unauthenticated attacker to interact with internal services to modify the credentials of non-federated administrative or tenant accounts.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational data integrity and system access control. By resetting administrative passwords, an attacker can gain unauthorized access to the StorageGRID environment, potentially leading to total compromise of managed data and configuration. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized administrative escalation.
Remediation
Immediate Action: Upgrade NetApp StorageGRID instances to version 11.8.0.15, 11.9.0.8, or later, as specified in the official NetApp security advisory.
Proactive Monitoring: Review administrative audit logs for unusual password change events or unexplained authentication activity associated with non-federated accounts.
Compensating Controls: If patching is delayed, ensure Single Sign-on (SSO) is enabled, which mitigates the current vulnerability, and restrict network access to the Grid Manager and Tenant Manager interfaces via firewall rules.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk posed by this vulnerability is significant due to the potential for complete administrative account takeover. Administrators should prioritize the application of the provided security updates immediately. If immediate patching is not feasible, verify the deployment of Single Sign-on configurations to reduce the attack surface until the software can be updated.