Junglewise Threat Intelligence

CVE-2026-22051: NetApp StorageGRID information disclosure via arbitrary metrics queries

CVE-2026-22051 · Severity: medium · CVSS 4.3 · Published 2026-04-20

Vendors: NetApp.

Executive brief

NetApp StorageGRID, a scalable object storage solution, is affected by a security flaw that allows unauthorized access to system metrics. An attacker with low-level access to the system could run restricted queries to view performance and operational data they are not supposed to see. While this does not allow for the modification or deletion of data, it could expose sensitive information about the storage environment's configuration and usage.

Technical details

An information disclosure vulnerability (CWE-200) exists in NetApp StorageGRID (formerly StorageGRID Webscale) due to improper access control on metrics query endpoints. An authenticated attacker with low privileges can bypass intended restrictions to execute arbitrary metrics queries via the network. This allows the attacker to retrieve metric results and system telemetry that should be restricted to higher-privileged accounts. The issue is resolved in StorageGRID versions 11.9.0.13 and 12.0.0.6.

Affected products

  • NetApp StorageGRID versions prior to 11.9.0.13 and 12.0.0.6

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory

References

Related threats