Sceawere

Vulnerability Detail

CVE-2026-13460UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Storage Scale Hardcoded Token Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
IBM
Product
Storage Scale
Attack Type
CWE-798 Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T20:17:14.010Z",
  "pubdate": "2026-08-13T20:17:14.010Z",
  "executiveSummary": "A hardcoded token vulnerability has been identified in the graphical user interface (GUI) component of IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0. This cryptographic or authentication flaw stems from the inclusion of a static, hardcoded secret directly within the application source code. The affected component utilizes this hardcoded token for inter-node cluster communication and REST API authentication between GUI services.\nThe presence of a static credential introduces significant risk implications for enterprise deployments, potentially allowing unauthorized actors to bypass authentication mechanisms entirely. An attacker possessing network visibility to the GUI or inter-node communication channels can leverage the extracted token to forge valid authentication sessions or impersonate authorized nodes within the cluster architecture. Depending on the privileges associated with the hardcoded token, successful exploitation could lead to unauthorized administrative access, information disclosure, or manipulation of cluster management functionalities.\nNo specific preconditions beyond network access to the vulnerable endpoints or services relying on the token are detailed in the exploitation requirements. Mitigation requires applying official vendor patches or updates as supplied by IBM to remove the hardcoded secret and enforce dynamic credential generation or secure key exchange protocols.",
  "technicalDetails": "The root cause of this vulnerability lies in secure development lifecycle oversights where a static cryptographic secret, API key, or authentication token was hardcoded into the source code of the IBM Storage Scale GUI component rather than being dynamically generated during installation or provisioned securely via environment variables and secure configuration stores.\nThe vulnerable components are the GUI and the underlying services responsible for inter-node cluster communication and REST API authentication between GUI instances. Because the token is embedded statically within the application binary or script files, any user or process with read access to the source code, installation packages, or network traffic analysis capabilities can extract the credential.\nThe attack flow proceeds as follows: First, an adversary obtains the hardcoded token either by reverse engineering the application binaries or source code files distributed within the affected IBM Storage Scale versions, or by capturing traffic where the token is utilized statically. Second, the attacker formulates HTTP requests to the REST API endpoints of the GUI or initiates inter-node communications using the extracted token within the authentication headers or payload parameters. Third, because the receiving application or node relies on a hardcoded validation check against the identical static value, the authentication routine validates the request as authentic.\nUpon successful validation, the attacker is granted unauthorized access to the REST API or cluster communication channels with the privileges tied to the token. This authentication bypass requires network exposure to the affected GUI ports or cluster management interfaces. Depending on the role and privilege level associated with the hardcoded inter-node or REST API token, post-exploitation impact may include full administrative control over the storage management plane, execution of privileged API commands, retrieval of sensitive operational data, or disruption of storage cluster operations."
}
CVE-2026-13460: IBM Storage Scale Hardcoded Token Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere