Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (management interface privilege bypass): An authenticated low-privileged user reaches
CVSS 8.6CVE-2026-6444Control plane, storage & DevOpscurated
Impact
An authenticated low-privileged user reaches functionality beyond their assigned privileges in the array management interface - horizontal and vertical RBAC bypass on the storage control plane.
Who can reach it
Authenticated low-privilege user of the Purity management interface.
What to do
Apply the Purity update per Pure's security bulletins; review array RBAC assignments afterwards.
References
Related entries
- rclone (serve restic): Path validation in serve restic is incomplete, so an authenticated caller escapes the configuredCVE-2026-71309 · rclone (serve restic)High
- LibreNMS: device hostname is concatenated into shell commands in libvirt discovery, giving RCECVE-2026-84194 · LibreNMS libvirt VM discovery (VminfoLibvirt.php)High
- VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/writeCVE-2024-22280 · VMware Aria Automation (SQL injection)High
- Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSXCVE-2025-11198 · Juniper Security Director Policy Enforcer (vSRX image upload)High
- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareCVE-2025-22218 · VMware Aria Operations for Logs (credential disclosure)High
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.