CVE-2026-22052
Received
Received - Intake
Information Disclosure in NetApp ONTAP S3 NAS Buckets
Publication date: 2026-03-05
Last updated on: 2026-03-13
Assigner: NetApp, Inc.
Description
Description
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | ontap | 9 |
| netapp | ontap | From 9.12.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |