The flaw, tracked as CVE-2026-23594, could allow a remote attacker with low-level access to gain full administrative control on affected systems.
The issue is described in Security Bulletin HPESBST04995 rev.1, published on 20 January 2026 and last updated on 21 January 2026.
HPE classifies the impact as “Remote: Increased Privilege”, meaning the attacker can elevate their permissions once they can connect to the device.
The vulnerability exists in certain configurations of HPE Alletra 6000, HPE Alletra 5000, and HPE Nimble Storage Array OS.
According to HPE, a remote attacker with low privileges can exploit this flaw to escalate to higher privileges, including administrative access.
HPE rates the bug with a CVSS v3.1 base score of 8.8 (High), using the following vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
This score indicates:
In practice, this means that once an attacker has basic authenticated access over the network, they may be able to compromise the storage system fully.
HPE notes that only specific versions of Alletra OS / Nimble OS are impacted. Systems running the following versions are vulnerable:
HPE has released the following updates to address the flaw:
| CVE ID | Severity (CVSS v3.1) | Vector | Impact | Affected Products / Versions | Fixed Versions |
|---|---|---|---|---|---|
| CVE-2026-23594 | 8.8 (High) | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Remote privilege escalation to admin | HPE Alletra 6000, Alletra 5000, Nimble Storage Hybrid Flash & All Flash Arrays – OS < 6.1.2.800; 6.1.3 < 6.1.3.300 | 6.1.2.800, 6.1.3.300 |
Administrators should:
HPE customers can contact HPE support or the HPE Product Security Response Team for assistance in implementing these fixes or reporting new issues.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post HPE Alletra and Nimble Storage Vulnerability Allows Remote Attackers to Gain Admin Access appeared first on Cyber Security News.
Jostling a folded piece of paper, holding it marooned in the air, selectman Beth Blair…
Boscawen voters cruised through a speedy town meeting Friday night, one with so little controversy…
Happy Saturday, all! This week, we found a number of deals that should help you…
Though it was weird to see the Golden Globes partner with Polymarket for its most…
Neo to the left of me. Pros are to the right. | Photo: Antonio G.…
Zendesk is to acquire Forethought AI. It says that this will be its largest acquisition…
This website uses cookies.