← Vulnerability feed

Vulnerability record · CVE-2026-22049 · published 22 July 2026

CVE-2026-22049: Netapp ontap authentication bypass via alternate path vulnerability

NNetapp · Ontap

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

8.7 CVSS 4.0 High EPSS 0.53% · top 57.4% CWE-288 · Authentication bypass via alternate path
8.7CVSS 4.0 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
20 Aug 2026Last modified by NVD

Description

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22049 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2024-8932Php out-of-bounds write vulnerabilityIn PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…EPSS 1.3%8.1CVE-2024-38473Apache http server vulnerabilityEncoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, po…EPSS 26%8.1CVE-2024-6387OpenSSH sshd signal handler race condition allows unauthenticated remote code executionA security regression of CVE-2006-5051 in OpenSSH's sshd creates a race condition where signals are handled unsafely. An unauthenticated remote attac…EPSS 100%analysed7.7CVE-2025-24928Netapp active iq unified manager stack-based buffer overflow vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation …EPSS 0.39%7.5CVE-2024-39573Apache http server improper input validation vulnerabilityPotential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to…EPSS 37%7.5CVE-2024-38472Apache HTTP Server on Windows SSRF leaks NTLM hashesApache HTTP Server on Windows is vulnerable to server-side request forgery that can cause the server to send NTLM authentication to an attacker-contr…EPSS 69%analysed7.5CVE-2024-27316Apache HTTP Server HTTP/2 header flood causes memory exhaustionApache HTTP Server buffers incoming HTTP/2 headers that exceed the configured limit in nghttp2 so it can return an HTTP 413 response. If the client k…EPSS 91%analysed

Source: NIST National Vulnerability Database (record CVE-2026-22049), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.