StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/NTAP-20260217-0001 |
|
History
Tue, 17 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: netapp
Published: 2026-02-17T23:01:30.331Z
Updated: 2026-02-17T23:01:30.331Z
Reserved: 2026-01-05T22:47:18.701Z
Link: CVE-2026-22048
No data.
Status : Received
Published: 2026-02-18T00:16:18.700
Modified: 2026-02-18T00:16:18.700
Link: CVE-2026-22048
No data.