CVE-2026-22052: Netapp Ontap

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.

Affected products

  • Netapp Ontap: from 9.12.1; version 9 only

Published 2026-03-05. Last modified 2026-06-17.