ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/NTAP-20260722-0001/ |
|
History
Thu, 23 Jul 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp ontap 9 |
|
| Vendors & Products |
Netapp
Netapp ontap 9 |
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-288 | |
| Metrics |
ssvc
|
Wed, 22 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: netapp
Published:
Updated: 2026-07-22T19:09:04.900Z
Reserved: 2026-01-05T22:47:18.701Z
Link: CVE-2026-22049
Updated: 2026-07-22T19:08:56.782Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T01:15:02Z
Weaknesses