{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-13T00:25:12.202","vulnerabilities":[{"cve":{"id":"CVE-2025-26514","sourceIdentifier":"security-alert@netapp.com","published":"2025-09-19T19:15:38.367","lastModified":"2025-09-23T14:32:00.057","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"StorageGRID (formerly \nStorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are \nsusceptible to a Reflected Cross-Site Scripting vulnerability. \nSuccessful exploit could allow an attacker to view or modify \nconfiguration settings or add or modify user accounts but requires the \nattacker to know specific information about the target instance and then\n trick a privileged user into clicking a specially crafted link."}],"metrics":{"cvssMetricV31":[{"source":"security-alert@netapp.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":4.7}]},"weaknesses":[{"source":"security-alert@netapp.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*","versionEndExcluding":"11.8.0.15","matchCriteriaId":"52CC3E7A-9725-45F5-805E-9E135B8E69E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.0.8","matchCriteriaId":"AF444D2C-DE7F-424A-B735-5697CD129016"}]}]}],"references":[{"url":"https://security.netapp.com/advisory/NTAP-20250910-0001","source":"security-alert@netapp.com","tags":["Vendor Advisory"]}]}}]}