Executive brief
NetApp Active IQ OneCollect, a tool used for collecting diagnostic data from storage environments, contains hard-coded credentials. An attacker who already has low-level access to the system could use these credentials to perform unauthorized AutoSupport operations. This could lead to unauthorized data transmissions or interference with automated support services.
Technical details
A hard-coded credentials vulnerability exists in NetApp Active IQ OneCollect version 2.7.3. The flaw allows an authenticated user with low-level privileges to discover and utilize static credentials embedded within the software. By leveraging these credentials, an attacker can perform unauthorized AutoSupport operations via the network. The vulnerability is tracked as CVE-2026-22055 and has been assigned a CVSS 4.0 base score of 5.3 by the vendor. Users are advised to consult NetApp security advisories for patching information.
Affected products
- NetApp Active IQ OneCollect 2.7.3
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory