{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-26514","assignerOrgId":"11fdca00-0482-4c88-a206-37f9c182c87d","state":"PUBLISHED","assignerShortName":"netapp","dateReserved":"2025-02-11T21:58:04.395Z","datePublished":"2025-09-19T18:31:54.948Z","dateUpdated":"2025-09-19T18:49:58.274Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"StorageGRID","vendor":"NetApp","versions":[{"lessThan":"11.8.0.15","status":"affected","version":"0","versionType":"custom"},{"lessThan":"11.9.0.8","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><div><p>\n</p><div><div><p>StorageGRID (formerly \nStorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are \nsusceptible to a Reflected Cross-Site Scripting vulnerability. \nSuccessful exploit could allow an attacker to view or modify \nconfiguration settings or add or modify user accounts but requires the \nattacker to know specific information about the target instance and then\n trick a privileged user into clicking a specially crafted link.</p>\n</div></div>\n\n<p></p>\n</div></div>"}],"value":"StorageGRID (formerly \nStorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are \nsusceptible to a Reflected Cross-Site Scripting vulnerability. \nSuccessful exploit could allow an attacker to view or modify \nconfiguration settings or add or modify user accounts but requires the \nattacker to know specific information about the target instance and then\n trick a privileged user into clicking a specially crafted link."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"11fdca00-0482-4c88-a206-37f9c182c87d","shortName":"netapp","dateUpdated":"2025-09-19T18:31:54.948Z"},"references":[{"url":"https://security.netapp.com/advisory/NTAP-20250910-0001"}],"source":{"advisory":"NTAP-20250910-0001","discovery":"UNKNOWN"},"title":"CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-09-19T18:49:45.652444Z","id":"CVE-2025-26514","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-09-19T18:49:58.274Z"}}]}}