What is CVE-2026-22049?
CVE-2026-22049 is a vulnerability in ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured, related to the Relying Party ID. Successful exploitation could allow an attacker with valid credentials to bypass MFA. It is recommended to review MFA implementation and apply available updates on affected systems.
Azərbaycanca: CVE-2026-22049, WebAuthn çoxfaktorlu autentifikasiyası (MFA) konfiqurasiya edilmiş ONTAP 9.16.1 və daha yuxarı versiyalarında Relying Party ID ilə bağlı zəiflikdir. Etibarlı hesab məlumatlarına malik hücumçu bu zəiflikdən istifadə edərək MFA mühafizəsini keçə bilər. Təsirlənən sistemlərdə MFA-nın düzgün tətbiqini yoxlamaq və mümkün yeniləmələri tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which NetApp ONTAP versions are affected by CVE-2026-22049?
This vulnerability affects ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured.
What can an attacker achieve by exploiting CVE-2026-22049?
An attacker with valid credentials can bypass MFA by exploiting this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.