Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/NTAP-20260217-0001 |
|
Sat, 18 Apr 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF in NetApp StorageGRID with Microsoft Entra ID SSO |
Wed, 18 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
ssvc
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp storagegrid |
|
| Vendors & Products |
Netapp
Netapp storagegrid |
Tue, 17 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: netapp
Published:
Updated: 2026-02-18T13:44:08.177Z
Reserved: 2026-01-05T22:47:18.701Z
Link: CVE-2026-22048
Updated: 2026-02-18T13:44:03.157Z
Status : Deferred
Published: 2026-02-18T00:16:18.700
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-22048
No data.
OpenCVE Enrichment
Updated: 2026-04-18T12:15:15Z