Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposes
CVSS 8.7CVE-2026-6445Control plane, storage & DevOpscurated
Impact
Insufficient filtering on certain data paths exposes sensitive information to an authenticated low-privileged user of the array.
Who can reach it
Authenticated low-privilege array user.
What to do
Apply the Purity update referenced in Pure's security bulletins. Non-disruptive array software upgrade.
References
Related entries
- SeaweedFS S3 API: raw OIDC JWT bypasses IAM role trust policy and grants that role's bucket accessCVE-2026-77298 · SeaweedFS S3 API (direct OIDC bearer token to IAM role mapping)High
- OpenNebula: one.vm.exec skips the permission check, letting any user run commands in other tenants' VMsCVE-2026-84165 · OpenNebula (one.vm.exec API authorization)High
- GitLab: stored XSS through merge request diff paths runs script in another user's sessionCVE-2026-84739 · GitLab CE/EE merge request diff viewer (path component sanitization)High
- HPE iLO3/4/5: Remote unauthenticated denial of service against the management controllerCVE-2018-7093 · HPE iLO3/4/5High
- NAKIVO Backup & Replication: Unauthenticated absolute path traversal via getImageByPathCVE-2024-48248 · NAKIVO Backup & ReplicationHigh
- Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP): A large cluster of unauthenticated ModbusCVE-2024-48882 · Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.