Database/Control plane, storage & DevOps
Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeover
Impact
Oracle describes this as an easily exploitable flaw that lets a high-privileged attacker with HTTP access take over the ZFS Storage Appliance Kit, with high confidentiality, integrity and availability impact. Where a ZFS appliance backs a training or inference fleet, that is control of the dataset and checkpoint store for every tenant on it - read, tamper or deny. Loss of availability on a shared NAS does not stop at one node: jobs across the cluster stall together, and a storage outage is not something a single node drain works around. The record gives no technical mechanism beyond the affected component.
Who can reach it
Network access to the appliance over HTTP, holding high privileges on the appliance (an administrative account or equivalent). Not an unauthenticated path, so exposure depends on who can reach the management interface and who holds admin credentials.
What to do
Apply the fix from the Oracle October 2025 Critical Patch Update for the ZFS Storage Appliance Kit 8.8. Patching an appliance controller means a service window on the storage head - on a single-head deployment the share goes away for the duration, and on a clustered pair you take one head at a time and accept degraded failover in between. Oracle does not publish a workaround; restricting network reach to the appliance management interface narrows the exposure in the meantime.
References
Related entries
- AMD CPUs - attacker influence over RDSEED entropy: A local attacker can influence the values RDSEED returns, causingCVE-2025-62626 · AMD CPUs - attacker influence over RDSEED entropyHigh
- Dell OpenManage Enterprise: unauthenticated SSRF reaches services on the management networkCVE-2026-54794 · Dell OpenManage Enterprise (web interface)High
- Dell OpenManage Enterprise: privileged user can inject OS commands and run code on the applianceCVE-2026-54796 · Dell OpenManage Enterprise (OS command handling)High
- Ivanti Endpoint Manager Mobile: Improper input validationCVE-2026-6973 · Ivanti Endpoint Manager MobileHigh
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherCVE-2026-70421 · Dell OpenManage Enterprise (privilege management)High
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointCVE-2026-75786 · Pandora FMS (Grafana datasource endpoint, module parameter)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.