Cyber Security News

HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker

A critical privilege escalation vulnerability affecting multiple storage platforms could allow remote attackers to gain administrative access without physical interaction.

The flaw, tracked as CVE-2026-23594, impacts HPE Alletra 6000, Alletra 5000, and Nimble Storage arrays running vulnerable firmware versions.

The vulnerability exists in specific configurations of the affected storage operating systems and enables remote privilege elevation when exploited.

With a CVSS v3.1 score of 8.8 (High), the flaw requires low attack complexity and only low-level privileges to exploit, making it particularly dangerous for enterprise environments where storage systems are network-accessible.​

CVE IDCVSS 3.1 VectorCVSS ScoreSeverityImpact TypeAttack Vector
CVE-2026-23594​CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H​8.8​HighRemote Privilege Elevation​Network​

According to HPE’s security bulletin HPESBST04995, successful exploitation grants attackers high impact across confidentiality, integrity, and availability, effectively providing complete system compromise.

The attack vector is network-based with no user interaction required, allowing threat actors to escalate from limited user accounts to complete administrative control.​

Affected Products and Versions

The vulnerability affects multiple HPE storage product lines running Array OS versions before the patched releases.

Organizations using the following platforms should prioritize remediation:

ProductAffected Versions
HPE Alletra 6000< 6.1.2.8006.1.3 < 6.1.3.300
HPE Alletra 5000< 6.1.2.8006.1.3 < 6.1.3.300
Nimble Storage Hybrid Flash< 6.1.2.8006.1.3 < 6.1.3.300
Nimble Storage All Flash< 6.1.2.8006.1.3 < 6.1.3.300

HPE released security patches on January 20, 2026, to address the privilege escalation flaw.

Administrators should immediately upgrade vulnerable systems to one of the following patched versions: Alletra OS 6.1.2.800, Alletra OS 6.1.3.300​.

The patches eliminate the configuration weakness that allowed privilege escalation, restoring proper access controls within the storage management interface.

Enterprise storage systems frequently contain business-critical data and serve as single points of failure for production environments.

Unauthorized administrative access could enable attackers to exfiltrate sensitive information, deploy ransomware, or disrupt storage operations across entire data centers.

Organizations should treat this vulnerability as a high priority and deploy patches in accordance with their change management procedures.

HPE recommends that customers apply third-party security patches in accordance with established patch management policies and contact HPE Services support for assistance with implementation.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago