CVE-2026-22054: Medium severity NetApp Active IQ Config Advisor vulnerability
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetApp Active IQ Config Advisorto a version that resolves this vulnerability.Fixed in 6.7.3 - Operational
Update NetApp Active IQ Config Advisor to address the hard-coded credentials that allow unauthorized AutoSupport operations.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22054?
The severity of CVE-2026-22054 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-22054?
To fix CVE-2026-22054, update to the latest version of NetApp Active IQ Config Advisor that addresses the hard-coded credentials issue.
What kind of vulnerability is CVE-2026-22054?
CVE-2026-22054 is a vulnerability involving hard-coded credentials that allows authenticated low-privileged attackers to perform unauthorized operations.
Who is affected by CVE-2026-22054?
Users of Active IQ Config Advisor version 6.7.3 are affected by CVE-2026-22054 due to the presence of hard-coded credentials.
What can an attacker potentially do with CVE-2026-22054?
An attacker exploiting CVE-2026-22054 could perform unauthorized AutoSupport operations based on their low privileges.