{"id":"CVE-2025-36255","title":"IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.","summary":"IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-267"],"vendor":"ibm","product":"ds8900f_firmware","affected":["ds8900f_firmware >= 89.40.83.0, <= 89.44.25.0","ds8a00_firmware >= 10.1.3.0, <= 10.11.35.0"],"published":"2026-08-19","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:10:00.263","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36255","references":[{"url":"https://www.ibm.com/support/pages/node/7284322","label":"psirt@us.ibm.com"}],"tags":["nvd"],"ingestedAt":"2026-09-29T10:31:36.300Z","slug":"CVE-2025-36255","body":"## Overview\n\nIBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.\n\n## Affected\n\n- `ds8900f_firmware >= 89.40.83.0, <= 89.44.25.0`\n- `ds8a00_firmware >= 10.1.3.0, <= 10.11.35.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}