CVE-2026-22050
Snapshot Expiry Bypass in NetApp ONTAP Allows Privileged Remote Attack
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: NetApp, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | ontap | to 9.16.1P9 (exc) |
| netapp | ontap | to 9.17.1P2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 when snapshot locking is enabled. It allows a privileged remote attacker to set the snapshot expiry time to none, potentially preventing snapshots from expiring as intended.
How can this vulnerability impact me? :
The vulnerability could allow a privileged remote attacker to prevent snapshots from expiring by setting their expiry time to none. This may lead to storage management issues such as accumulation of snapshots, increased storage consumption, and potential disruption of backup or recovery processes.