CVE-2026-22056: Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
Published Aug 28, 2026
·Updated
StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service.
Affected Software
1 affected component
NetApp Storagegrid>=undefined
Event History
Aug 28, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Prioritize StorageGRID versions 11.5 and higher that use the affected non-standard configuration and scenario, particularly where an attacker could obtain some control over the environment.
2
What level of access or control does an attacker need?
Successful exploitation requires an attacker to have some control over the environment. The available information does not describe a fully remote, unauthenticated attack path.
3
What is the expected operational impact?
A successful exploit could cause a partial denial of service rather than a complete outage.