HarborGuard / CVE
Back to search
HIGHCVE-2026-22048Published Modified CNA netapp

CVE-2026-22048: StorageGRID (formerly StorageGRID Webscale) versions prior to 11

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
11.9.0.12
Affected Products
1

Fix available

11.9.0.1212.0.0.4
Affected packages
  • NETAPP / StorageGRID (formerly StorageGRID Webscale)
    < 11.9.0.12 (from 0) · < 12.0.0.4 (from 12.0.0.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H