Executive brief
NetApp Active IQ Config Advisor, a tool used to validate the configuration and health of NetApp storage systems, contains hard-coded credentials. An attacker who already has low-level access to the system could use these credentials to perform unauthorized AutoSupport operations. This could lead to unauthorized data transmissions or configuration changes within the support reporting framework.
Technical details
A hard-coded credentials vulnerability exists in NetApp Active IQ Config Advisor version 6.7.3. The flaw is located within the handling of AutoSupport operations, where static credentials are used instead of dynamic or user-defined authentication. An attacker with network access and low-privileged authentication can discover and reuse these credentials to trigger or manipulate AutoSupport functions. This could result in unauthorized communication with NetApp support infrastructure or disclosure of system diagnostic information. The vulnerability is tracked as CVE-2026-22054 and has been assigned a CVSS 4.0 base score of 5.3 by the vendor.
Affected products
- NetApp Active IQ Config Advisor 6.7.3
Timeline
- 2026-06-03: advisory: NetApp published the security advisory NTAP-20260603-0001.
- 2026-06-03: disclosed: CVE-2026-22054 was published to the NVD.