CVE-2026-22049: High severity NetApp Ontap vulnerability
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22049?
CVE-2026-22049 is rated with a risk level of 50.
How do I fix CVE-2026-22049?
To mitigate CVE-2026-22049, ensure your ONTAP version is updated to the latest release provided by NetApp that addresses this vulnerability.
What is the impact of CVE-2026-22049?
CVE-2026-22049 allows an attacker with valid credentials to bypass multi-factor authentication on affected ONTAP versions.
Which versions are affected by CVE-2026-22049?
CVE-2026-22049 affects ONTAP versions 9.16.1 and higher that have WebAuthn multi-factor authentication configured.
Who is affected by CVE-2026-22049?
Organizations using NetApp ONTAP versions 9.16.1 and above with WebAuthn MFA configurations are at risk from CVE-2026-22049.