{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-13460/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13460"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Storage Scale 5.2.3.0 through 5.2.3.8","Storage Scale 6.0.0.0 through 6.0.1.0","Storage Scale"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","cve-2026-13460"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a security vulnerability (CVE-2026-13460) affecting the GUI component of IBM Storage Scale. The vulnerability arises from a hardcoded token embedded within the source code, which is utilized for inter-node cluster communication and REST API authentication between GUI instances. An unauthenticated, network-adjacent attacker could potentially leverage this hardcoded credential to bypass authentication mechanisms, gain unauthorized access to the management interface, or intercept/manipulate cluster communication. The vulnerability affects Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0. Given the high CVSS score of 7.5, organizations deploying these versions of IBM Storage Scale should prioritize the application of vendor-provided patches to mitigate the risk of unauthorized administrative access or cluster compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could grant an attacker unauthorized access to the Storage Scale GUI. As the hardcoded token is used for authentication, an attacker could potentially gain administrative control over the cluster's management layer. This could lead to sensitive data exfiltration, unauthorized configuration changes, or the disruption of storage services across the affected cluster.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches provided by IBM in the official security advisory (\u003ca href=\"https://www.ibm.com/support/pages/node/7283308\"\u003ehttps://www.ibm.com/support/pages/node/7283308\u003c/a\u003e) immediately.\u003c/li\u003e\n\u003cli\u003eAudit network access controls for the Storage Scale GUI to ensure that only authorized administrative workstations or management subnets have access to the management interface.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious API requests or unauthorized attempts to access management endpoints using static or unusual token headers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T22:08:47Z","date_published":"2026-08-13T22:05:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-storage-scale-hardcoded-token/","summary":"IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 contain a hardcoded token used for inter-node communication and REST API authentication, allowing potential unauthenticated access to the GUI.","title":"Hardcoded Authentication Token in IBM Storage Scale GUI","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-storage-scale-hardcoded-token/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-13460","version":"https://jsonfeed.org/version/1.1"}