CVE-2026-0207 is a vulnerability in FlashBlade that permits sensitive information to be logged under specific circumstances, potentially exposing confidential data through system log files. The vulnerability affects FlashBlade systems and has been assigned a FAUCET Risk Score of 41.0 out of 100, indicating moderate concern from a risk perspective. The attack vector and complexity metrics are currently not available, limiting detailed severity assessment at this time. However, the extremely low EPSS score of 0.00016 suggests minimal probability of exploitation in real-world scenarios, placing this vulnerability in the lower percentile of all publicly disclosed CVEs in terms of practical exploitability. There is no evidence of active exploitation or public exploit code availability for this vulnerability. The CVE is not listed on the Known Exploited Vulnerabilities catalog, and it remains inactive on the Hot List, indicating minimal community attention and no confirmed instances of in-the-wild exploitation. Organizations should prioritize patching based on their FlashBlade deployment criticality and data sensitivity rather than perceived urgency from threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PureStorage | FlashBlade | >= 4.0.0, <= 4.4.8, >= 4.5.0, <= 4.5.13, >= 4.6.0, <= 4.6.3CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.