PT-2026-23079 · Netapp · Netapp Ontap

Published

2026-03-04

·

Updated

2026-03-13

·

CVE-2026-22052

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NetApp ONTAP versions 9.12.1 and higher
Description An information disclosure issue exists in NetApp ONTAP S3 NAS buckets. A successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
Recommendations Update to a newer version of NetApp ONTAP.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-22052

Affected Products

Netapp Ontap