StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/NTAP-20260217-0001 |
|
History
Wed, 18 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
ssvc
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp storagegrid |
|
| Vendors & Products |
Netapp
Netapp storagegrid |
Tue, 17 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: netapp
Published: 2026-02-17T23:01:30.331Z
Updated: 2026-02-18T13:44:08.177Z
Reserved: 2026-01-05T22:47:18.701Z
Link: CVE-2026-22048
Updated: 2026-02-18T13:44:03.157Z
Status : Awaiting Analysis
Published: 2026-02-18T00:16:18.700
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-22048
No data.
ReportizFlow