Database/Control plane, storage & DevOps

IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI available
Impact
A local privilege escalation in the Storage Scale GUI available to an actor with command-line access to the GUI service account. Escalating to root on a GUI node is escalating on a node that holds cluster-wide storage credentials, which is why this scores higher operationally than 'it's just the web UI' suggests.
Who can reach it
Local, requires command-line access as the GUI service user on Storage Scale GUI 5.1.9.0-5.1.9.6 or 5.2.0.0-5.2.1.1.
What to do
Upgrade the Storage Scale GUI. Service-level upgrade with a restart; filesystem I/O is unaffected. Companion CSV-handling issue CVE-2024-31892 is fixed in the same range.
References
Related entries
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDCVE-2024-46746 · Linux HID/amd_sfh - driver_data freed after HID device destructionHigh
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itCVE-2026-11332 · ansible-core (ansible-galaxy role install, git argument injection via meta/requirements.yml)High
- ansible-core: git argument injection in ansible-galaxy collection install yields command executionCVE-2026-16493 · ansible-core (ansible-galaxy collection install, git source URL handling)High
- MUNGE (munged credential daemon): This is the root of trust under Slurm. A crafted message with an oversizedCVE-2026-25506 · MUNGE (munged credential daemon)High
- VMware Avi Load Balancer: local user can escalate to root on the applianceCVE-2026-47868 · VMware Avi Load Balancer (Controller and Service Engine appliance)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.