CVE-2026-22051
Last modified
CVE-2026-22051 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Storagegrid | < 11.9.0.13 |
| Netapp | Storagegrid | >= 12.0, < 12.0.0.6 |
References
- https://security.netapp.com/advisory/ntap-20260420-0001Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22051?
How severe is CVE-2026-22051?
How do I fix CVE-2026-22051?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22046iccDEV provides a set of libraries and tools that allow for …8.8
- CVE-2026-22047iccDEV provides a set of libraries and tools that allow for …8.8
- CVE-2026-22048StorageGRID (formerly StorageGRID Webscale) versions prior t…7.1
- CVE-2026-22049ONTAP versions 9.16.1 and higher with WebAuthn multi-factor …8.8
- CVE-2026-2205A vulnerability was identified in WeKan up to 8.20. This aff…5.3
- CVE-2026-22050ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to …4.3
- CVE-2026-22052ONTAP versions 9.12.1 and higher with S3 NAS buckets are sus…4.3
- CVE-2026-22054Active IQ Config Advisor version 6.7.3 contains hard-coded c…8.8
- CVE-2026-22055Active IQ OneCollect version 2.7.3 contains hard-coded crede…8.8
- CVE-2026-22056StorageGRID (formerly StorageGRID Webscale) versions 11.5 an…2.3
- CVE-2026-2206A security flaw has been discovered in WeKan up to 8.20. Thi…8.8
- CVE-2026-22068Regular Expression without Anchors vulnerability in Apache T…5.3
Are you affected by CVE-2026-22051?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
