Information Disclosure Vulnerability in ONTAP by NetApp
CVE-2026-22052
5.3MEDIUM
What is CVE-2026-22052?
The ONTAP product line from NetApp, specifically versions 9.12.1 and above, is vulnerable to an information disclosure issue affecting S3 NAS buckets. This vulnerability allows an authenticated user to gain unauthorized access to directory listings, exposing sensitive content that they should not have permission to view. Such a flaw can lead to significant security risks, compromising data integrity and user privacy.
Affected Version(s)
ONTAP 9 9.12.1 and higher
