boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-36255

IBM DS8A00( R10.0 - R10.1 ) — DS8900F and DS8A00 Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0024   14.2     —
AFFECTED
  Product                  Versions      Fixed
  DS8A00( R10.0 - R10.1 )  10.1.3.0 –    —
  DS8900F ( R9.4)          89.40.83.0 –  —
TIMELINE
  Apr 15  Reserved by ibm
  Aug 19  Published (CNA: ibm)
  Aug 24  RESCORED — CVE-2025-36255 (IBM DS8A00( R10.0 - R10.1 )). CVSS 7.5 → 8.8 (NVD).
CWE-267 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 15, 2025ReservedReserved by ibm
August 19, 2026PublishedPublished (CNA: ibm)
August 24, 2026RESCOREDRESCORED — CVE-2025-36255 (IBM DS8A00( R10.0 - R10.1 )). CVSS 7.5 → 8.8 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
IBMDS8A00( R10.0 - R10.1 )—10.1.3.0—
IBMDS8900F ( R9.4)—89.40.83.0—

Weaknesses

CWE-267

References (1)

Related

Authoritative record: CVE-2025-36255 at cve.org

Vendors: ibm

Weaknesses: CWE-267

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-36255 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.