Skip to content
IBMCVE-2025-36255

IBM DS8900F: authenticated user could create a user with privileged user

High7.5CVE-2025-36255 · Published Aug 19, 2026 · updated Aug 24, 2026

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

IBM advisory

Affected versions

PackageAffectedFixed in
DS8900F ( R9.4)
Product
>= 89.40.83.0, <= 89.44.25.0No fix yet
DS8A00( R10.0 - R10.1 )
Product
>= 10.1.3.0, <= 10.11.35.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-267

More IBM advisories

All IBM
Advisory
IBM DS8900F (R9.4): information disclosure
High7.4Aug 19
IBM DS8900F (R9.4): authenticated user could read or modify another user's
Medium5.4Aug 19
IBM PowerVM Hypervisor Platform KeyStore
Medium5.1Aug 19
IBM PowerVM Hypervisor: local attacker could decrypt encrypted data
Medium5.3Aug 19
IBM go-slug: local attacker could bypass
Medium5.5Aug 19
IBM i: denial of service
Medium5.4Aug 19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.