Junglewise Threat Intelligence

CVE-2026-22049: NetApp ONTAP MFA bypass in WebAuthn

CVE-2026-22049 · Severity: info · CVSS 8.7 · Published 2026-07-22

Vendors: NetApp.

Executive brief

NetApp ONTAP, a data management software used for storage and file services, contains a security flaw in its multi-factor authentication (MFA) system. An attacker who already has a user's password could bypass the secondary security check (WebAuthn) to gain full access to the system. This could lead to unauthorized data access, modification, or service disruption.

Technical details

A vulnerability in NetApp ONTAP (versions 9.16.1 through 9.19.1) involves an improper implementation of the WebAuthn Relying Party ID. This flaw allows an attacker who has already obtained valid user credentials to bypass the multi-factor authentication (MFA) requirement. The issue is classified as an authentication bypass using an alternate path (CWE-288). Exploitation requires network access and low-privileged user credentials but no user interaction. Successful exploitation grants the attacker the same level of access as the compromised account, potentially leading to high impacts on confidentiality, integrity, and availability.

Affected products

  • NetApp ONTAP 9 9.16.1 to 9.19.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References