HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker
A critical privilege escalation vulnerability, identified as CVE-2026-23594, has been discovered in various HPE storage platforms. This flaw could allow remote attackers to gain administrative access without physical interaction.
A critical privilege escalation vulnerability, identified as CVE-2026-23594, has been discovered in various HPE storage platforms. This flaw could allow remote attackers to gain administrative access without physical interaction.
The vulnerability affects HPE Alletra 6000, Alletra 5000, and Nimble Storage arrays with certain firmware versions. It is present in specific configurations of the storage operating systems, allowing remote privilege elevation when exploited.
With a CVSS v3.1 score of 8.8, this vulnerability is classified as high severity. It requires low attack complexity and only low-level privileges for exploitation, posing a significant risk to enterprise environments with network-accessible storage systems.
CVE ID CVSS 3.1 Vector CVSS Score Severity Impact Type Attack Vector
CVE-2026-23594 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 8.8 High Remote Privilege Elevation Network
The vulnerability impacts several HPE storage product lines running Array OS versions prior to the patched releases. Organizations utilizing the following platforms should prioritize remediation:
A critical privilege escalation vulnerability, identified as CVE-2026-23594, has been discovered in various HPE storage platforms.
Product Affected Versions
HPE Alletra 6000 < 6.1.2.800, < 6.1.3.300
HPE Alletra 5000 < 6.1.2.800, < 6.1.3.300
Nimble Storage Hybrid Flash < 6.1.2.800, < 6.1.3.300
Nimble Storage All Flash < 6.1.2.800, < 6.1.3.300
HPE has issued security patches as of Mon, Jan 20, 2026, to address this privilege escalation vulnerability. Administrators should upgrade affected systems to patched versions: Alletra OS 6.1.2.800 or Alletra OS 6.1.3.300.
The patches correct the configuration weakness responsible for the privilege escalation, ensuring proper access controls are reinstated within the storage management interface.
Given the critical nature of enterprise storage systems, which often contain business-critical data, organizations should treat this vulnerability as a high priority. It is essential to deploy patches in accordance with established change management procedures to prevent unauthorized access, potential data exfiltration, ransomware deployment, or disruptions in storage operations.
HPE recommends applying third-party security patches according to established patch management policies and suggests contacting HPE Services support for assistance with implementation. More information can be found in the HPE security bulletin .
Based on reporting by Cyber Security News.
