CVE-2026-22048: SSRF
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22048?
CVE-2026-22048 is considered a critical vulnerability due to the potential for server-side request forgery (SSRF) attacks.
How do I fix CVE-2026-22048?
To remediate CVE-2026-22048, upgrade to NetApp StorageGRID version 11.9.0.12 or 12.0.0.4 or later.
What systems are affected by CVE-2026-22048?
CVE-2026-22048 affects NetApp StorageGRID versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled using Microsoft Entra ID.
What type of vulnerability is CVE-2026-22048?
CVE-2026-22048 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2026-22048 be exploited remotely?
Yes, CVE-2026-22048 can be exploited remotely if the conditions for the SSRF vulnerability are met.