CVE-2026-22052: Medium severity NetApp Ontap vulnerability
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22052?
CVE-2026-22052 is classified as a medium severity information disclosure vulnerability.
How do I fix CVE-2026-22052?
To mitigate CVE-2026-22052, ensure you upgrade your NetApp ONTAP version to the latest release that addresses this vulnerability.
Who is affected by CVE-2026-22052?
CVE-2026-22052 affects users of NetApp ONTAP versions 9.12.1 and higher with S3 NAS buckets configured.
What type of attack can exploit CVE-2026-22052?
An authenticated attacker could exploit CVE-2026-22052 to gain unauthorized visibility of directory contents.
What is the risk of not addressing CVE-2026-22052?
Failing to address CVE-2026-22052 may lead to unauthorized information disclosure, compromising sensitive data in S3 NAS buckets.