CVE-2026-13460

Summary

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.

Affected Software

VendorProductVersion RangeStatus
IBMStorage Scale5.2.3.0 <= 5.2.3.8affected
IBMStorage Scale6.0.0.0 <= 6.0.1.0affected

Weaknesses

  • CWE-798: CWE-798 Use of Hard-coded Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References