CVE-2026-13460 PUBLISHED

The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher

Assigner: ibm
Reserved: 26.06.2026 Published: 13.08.2026 Updated: 13.08.2026

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor IBM
Product Storage Scale
Versions
  • affected from 5.2.3.0 to 5.2.3.8 (incl.)
  • affected from 6.0.0.0 to 6.0.1.0 (incl.)

Solutions

For IBM Storage Scale 5.2.3.x, IBM strongly recommends addressing the vulnerability by upgrading to 5.2.3.9 or later:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=5.2.3&platform=All&function=all

For IBM Storage Scale 6.0.0.x, IBM strongly recommends addressing the vulnerability by upgrading to 6.0.1.1 or later:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=6.0.1&platform=All&function=all

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE