Junglewise Threat Intelligence

CVE-2026-6445: Pure Storage FlashArray Purity Information Exposure via Improper Path Filtering

CVE-2026-6445 · Severity: info · CVSS 8.7 · Published 2026-06-09

Executive brief

A security vulnerability in Pure Storage FlashArray Purity software could allow a user with low-level access to view sensitive information they are not authorized to see. This occurs because the system does not properly filter certain data requests, potentially leading to the exposure of internal data or configuration details. While an attacker must already have an account on the system, this flaw could be used to escalate their knowledge or impact the confidentiality of the storage environment.

Technical details

An improper authorization vulnerability (CWE-939) exists in Pure Storage FlashArray Purity due to insufficient filtering of specific data paths. An authenticated attacker with low-level privileges can exploit this flaw over the network to access sensitive information that should be restricted. The vulnerability is rooted in how the system handles custom URL schemes or specific data handlers, failing to properly validate the user's authorization for the requested path. Successful exploitation could lead to a high impact on confidentiality, integrity, and availability within the affected environment. Pure Storage has acknowledged the issue via a security bulletin.

Affected products

  • Pure Storage FlashArray Purity

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats