Database/Control plane, storage & DevOps

IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, used
Impact
A hardcoded token in the Storage Scale GUI source, used for inter-node cluster communication and REST access. A hardcoded credential in a storage cluster's management path is the same shipped-secret problem as default BMC passwords: it is identical on every deployment, it is in a source tree anyone can read, and rotating it is not something the product expects you to do.
Who can reach it
Anyone who can reach the Storage Scale GUI/REST endpoint and knows the token — which, once published, is everyone.
What to do
Upgrade Storage Scale past the affected 5.2.3.x / 6.0.x levels. GUI-layer upgrade plus service restart; the filesystem stays up. Immediately restrict the GUI/REST endpoint to a management network — a firewall change, applied live, that matters more than the patch timing.
References
Related entries
- Performance Co-Pilot: signed integer overflow in __pmGetPDU permanently blinds the collector daemonCVE-2026-16529 · Performance Co-Pilot pmcd/PMAPI (__pmGetPDU PDU length handling)High
- Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trust: This is the vendor formally concedingCVE-2026-32666 · Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trustHigh
- Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fixCVE-2026-34486 · Apache TomcatHigh
- JFrog Artifactory: internal anonymous-user token returned to unauthenticated callersCVE-2026-42018 · JFrog Artifactory (anonymous-user token disclosure)High
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointCVE-2026-42151 · Prometheus (Azure AD remote-write OAuth client_secret in /-/config)High
- Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memoryCVE-2026-42154 · Prometheus (/api/v1/read snappy decompression length handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.