nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6445 CVE-2026-6445
HIGH
Everpure FlashArray Purity Information Disclosure
Record summary
CVE-2026-6445 has a selected CVSS score of 8.7 (high).
Description
A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlashArrayBrowse Everpure / FlashArrayDefault status: unaffected | CVE List | 6.5.0 to ≤ 6.5.8 | affected |
| 6.10.0 to ≤ 6.10.5 | affected |
References
2support.purestorage.com
https://support.purestorage.com/bundle/m_security_bulletins/page/Pure_Security/topics/concept/c_security_bulletins.html