Skip to content
Threat Feed
high advisory

Hardcoded Authentication Token in IBM Storage Scale GUI

IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 contain a hardcoded token used for inter-node communication and REST API authentication, allowing potential unauthenticated access to the GUI.

CVE search metadata

CVE search record: CVE-2026-13460. Severity: high. CVSS: 7.5. KEV: no. Product: Storage Scale 5.2.3.0 through 5.2.3.8, Storage Scale 6.0.0.0 through 6.0.1.0, Storage Scale. Brief: Hardcoded Authentication Token in IBM Storage Scale GUI. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-storage-scale-hardcoded-token/

What's new

  • 1. added coverage for Storage Scale Aug 13, 22:08 via nvd

IBM has disclosed a security vulnerability (CVE-2026-13460) affecting the GUI component of IBM Storage Scale. The vulnerability arises from a hardcoded token embedded within the source code, which is utilized for inter-node cluster communication and REST API authentication between GUI instances. An unauthenticated, network-adjacent attacker could potentially leverage this hardcoded credential to bypass authentication mechanisms, gain unauthorized access to the management interface, or intercept/manipulate cluster communication. The vulnerability affects Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0. Given the high CVSS score of 7.5, organizations deploying these versions of IBM Storage Scale should prioritize the application of vendor-provided patches to mitigate the risk of unauthorized administrative access or cluster compromise.

Impact

Successful exploitation of this vulnerability could grant an attacker unauthorized access to the Storage Scale GUI. As the hardcoded token is used for authentication, an attacker could potentially gain administrative control over the cluster's management layer. This could lead to sensitive data exfiltration, unauthorized configuration changes, or the disruption of storage services across the affected cluster.

Recommendation

  • Apply the security patches provided by IBM in the official security advisory (https://www.ibm.com/support/pages/node/7283308) immediately.
  • Audit network access controls for the Storage Scale GUI to ensure that only authorized administrative workstations or management subnets have access to the management interface.
  • Monitor web server logs for suspicious API requests or unauthorized attempts to access management endpoints using static or unusual token headers.

Immediate actions

Patch IBM Storage Scale to the versions recommended in the IBM security advisory.

IT Operations 48h

Mitigations

Restrict network access to the IBM Storage Scale GUI management port.

immediate Network Engineering

CVE-2026-13460