PT-2026-2286 · Netapp · Ontap

Michele Damico

·

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2026-22050

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ONTAP versions 9.16.1 through 9.16.1P9 ONTAP versions 9.17.1 through 9.17.1P2
Description ONTAP systems with snapshot locking enabled may allow a privileged remote attacker to modify the snapshot expiry time to none.
Recommendations Update to ONTAP version 9.16.1P9 or later. Update to ONTAP version 9.17.1P2 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-22050

Affected Products

Ontap