CVE-2026-22049

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
References
Link Resource
https://security.netapp.com/advisory/NTAP-20260722-0001/ Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:netapp:ontap:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-22 19:16

Updated : 2026-08-20 12:43


NVD link : CVE-2026-22049

Mitre link : CVE-2026-22049

CVE.ORG link : CVE-2026-22049


JSON object : View

Products Affected

netapp

  • ontap
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel