CVE-2026-22049

EUVD-2026-47770
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
netappCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.75%
Affected Products (NVD)
VendorProductVersion
netappontap
9.16.1 ≤
𝑥
< 9.19.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
netappontap_9
9.16.1 ≤
𝑥
< 9.19.1
CNA