CVE-2025-36255CWE-267

CVE-2025-36255

High · published August 20, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
17.8
In the wild
Unconfirmed
What it is

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00262 · 17.8th percentile
Weakness
CWE-267 · Privilege Defined With Unsafe Actions
Published
2026-08-20T02:16Z
Affected products (2)
ProductVersionsFixed in
ibm/ds8900f_firmware≥ 89.40.83.0, ≤ 89.44.25.0
ibm/ds8a00_firmware≥ 10.1.3.0, ≤ 10.11.35.0
References (1)
EPSS history
Timeline
  • 19 AUG 21:22Z
    DS8900F and DS8A00 Privilege Escalation
    cvelistv5