GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, used

CVE-2026-13460Control plane, storage & DevOpscurated

Impact

A hardcoded token in the Storage Scale GUI source, used for inter-node cluster communication and REST access. A hardcoded credential in a storage cluster's management path is the same shipped-secret problem as default BMC passwords: it is identical on every deployment, it is in a source tree anyone can read, and rotating it is not something the product expects you to do.

Who can reach it

Anyone who can reach the Storage Scale GUI/REST endpoint and knows the token — which, once published, is everyone.

What to do

Upgrade Storage Scale past the affected 5.2.3.x / 6.0.x levels. GUI-layer upgrade plus service restart; the filesystem stays up. Immediately restrict the GUI/REST endpoint to a management network — a firewall change, applied live, that matters more than the patch timing.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.