Database/Control plane, storage & DevOps
Pure Storage FlashBlade logging: Sensitive material ends up in FlashBlade logs under certain conditions, and the scored
CVSS 8.5CVE-2026-0207Control plane, storage & DevOpscurated
Impact
Sensitive material ends up in FlashBlade logs under certain conditions, and the scored impact extends beyond the array itself - so whatever leaks is useful against adjacent systems, not just the storage.
Who can reach it
An account with high privileges on the array, or anyone able to read logs and support bundles collected from it.
What to do
Upgrade Purity//FB to the fixed release from Pure's bulletin, purge affected logs, and rotate any secret that could have been written into them.
References
Related entries
- GitLab package registry: authenticated path traversal that can lead to remote code executionCVE-2026-10053 · GitLab CE/EE package registryHigh
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
- GitLab EE: authenticated user can attribute AI usage to another namespaceCVE-2026-19228 · GitLab EE (AI feature usage attribution / request identity authorization)High
- open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handling: Three related defectsCVE-2026-44944 · open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handlingHigh
- GitLab EE: developer-level user can run a policy test pipeline and read protected CI/CD variablesCVE-2026-79708 · GitLab EE (security policy test pipelines, CI/CD variable scope validation)High
- GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCECVE-2026-88765 · GitLab EE (Advanced Search indexing, Unicode conversion buffer on project import)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.