CVE-2025-26512
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 266
Summary
CVE-2025-26512 is a vulnerability affecting SnapCenter versions below 6.0.1P1 and 6.1P1. This issue grants authenticated SnapCenter Server users the ability to elevate their privileges and assume administrative roles on remote systems where a SnapCenter plug-in is installed. Successful exploitation of this vulnerability could result in significant security implications, as unauthorized administrative access can lead to system compromise and data breaches. It is recommended that affected organizations promptly apply the available patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- NetApp SnapCenter
Affected Vendors
- NetApp