CVE-2025-26512

SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:snapcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:6.0.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:6.1:-:*:*:*:*:*:*

History

16 Jan 2026, 15:15

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://security.netapp.com/advisory/NTAP-20250324-0001 - () https://security.netapp.com/advisory/NTAP-20250324-0001 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20250324-0001/ - () https://security.netapp.com/advisory/ntap-20250324-0001/ - Vendor Advisory
First Time Netapp
Netapp snapcenter
CPE cpe:2.3:a:netapp:snapcenter:6.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:6.0.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:*:*:*:*:*:*:*:*

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) Las versiones de SnapCenter anteriores a 6.0.1P1 y 6.1P1 son susceptibles a una vulnerabilidad que puede permitir que un usuario autenticado del servidor SnapCenter se convierta en un usuario administrador en un sistema remoto donde se haya instalado un complemento de SnapCenter.

25 Mar 2025, 00:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250324-0001/ -

24 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-24 22:15

Updated : 2026-01-16 15:15


NVD link : CVE-2025-26512

Mitre link : CVE-2025-26512

CVE.ORG link : CVE-2025-26512


JSON object : View

Products Affected

netapp

  • snapcenter
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo