# CVE-2025-36255

## Summary

- **CVE ID:** CVE-2025-36255
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-267
- **Published:** Aug 19, 2026
- **Last Modified:** Aug 20, 2026

## Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

## Affected Products

- IBM — DS8A00( R10.0 - R10.1 ) (10.1.3.0)
- IBM — DS8900F ( R9.4) (89.40.83.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7284322)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 18.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._