CVE-2026-22048

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-18 00:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22048

Mitre link : CVE-2026-22048

CVE.ORG link : CVE-2026-22048


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)