HPE Alletra Nimble Flaw Gives Remote Admin Access
A critical vulnerability in HPE Alletra and Nimble Storage platforms could allow remote attackers to gain full administrative access, exposing enterprise networks to serious risks. Known as CVE-2026-23594, the HPE Alletra Nimble flaw affects specific versions of Alletra 6000, 5000, and Nimble Storage Hybrid and All Flash systems. It enables privilege escalation over the network without requiring user interaction.
With a CVSS score of 8.8, the flaw poses a high risk. Attackers can exploit it using only low-level access, compromising system confidentiality, integrity, and availability. HPE has released patches for affected systems, including Alletra OS 6.1.2.800 and 6.1.3.300, to address the issue.
Given the critical nature of enterprise storage, swift remediation is essential. HPE advises customers to apply updates through official channels and consult support if needed. The HPE Alletra Nimble flaw remains a pressing concern for organizations managing vital infrastructure.
HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker
