Description
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Storage Scale GUI contains a hardcoded token that is used for inter‑node cluster communication and REST API authentication. The presence of this secret is a flaw (CWE‑798) that could allow an attacker to impersonate node‑to‑node traffic or authenticate to APIs without proper credentials. If exploited, the attacker could gain administrative control over the cluster, potentially compromising confidentiality, integrity, and availability of stored data.

Affected Systems

IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 are affected. All newer releases starting at 5.2.3.9 and 6.0.1.1 include the fix.

Risk and Exploitability

The CVSS score of 7.5 classifies this as high severity. EPSS information is not available, so the exact probability of exploitation is unclear, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the REST API or inter‑node communication if an attacker can reach the affected nodes; this would permit unauthorized operations within the cluster.

Generated by OpenCVE AI on August 13, 2026 at 20:40 UTC.

Remediation

Vendor Solution

For IBM Storage Scale 5.2.3.x, IBM strongly recommends addressing the vulnerability by upgrading to 5.2.3.9 or later: https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=5.2.3&platform=All&function=all For IBM Storage Scale 6.0.0.x, IBM strongly recommends addressing the vulnerability by upgrading to 6.0.1.1 or later: https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=6.0.1&platform=All&function=all


OpenCVE Recommended Actions

  • Upgrade IBM Storage Scale to version 5.2.3.9 or later for the 5.2.x line
  • Upgrade to version 6.0.1.1 or later for the 6.0.x line
  • After upgrading, verify that cluster nodes and REST endpoints no longer use the hard‑coded token and that authentication is performed via secure credentials

Generated by OpenCVE AI on August 13, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
Title The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher
First Time appeared Ibm
Ibm storage Scale
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:storage_scale:5.2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:5.2.3.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:6.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:storage_scale:6.0.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm storage Scale
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Storage Scale
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:37:13.742Z

Reserved: 2026-06-26T20:00:24.929Z

Link: CVE-2026-13460

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:14.010

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-13460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:45:02Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials