Multi-Factor Authentication Bypass in ONTAP by NetApp
CVE-2026-22049
8.7HIGH
What is CVE-2026-22049?
A security vulnerability exists in ONTAP versions 9.16.1 and above, where a misconfiguration related to the Relying Party ID may allow attackers with valid credentials to bypass multi-factor authentication (MFA). This could expose sensitive data and systems to unauthorized access, highlighting the importance of proper MFA configuration and validation in safeguarding user accounts.
Affected Version(s)
ONTAP 9 9.16.1 < 9.19.1
