Database/Control plane, storage & DevOps
Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scored
CVE-2026-0207Control plane, storage & DevOpscurated
Impact
Sensitive material ends up in FlashBlade logs under certain conditions, and the scored impact extends beyond the array itself - so whatever leaks is useful against adjacent systems, not just the storage.
Who can reach it
An account with high privileges on the array, or anyone able to read logs and support bundles collected from it.
What to do
Upgrade Purity//FB to the fixed release from Pure's bulletin, purge affected logs, and rotate any secret that could have been written into them.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.