CVE-2026-22051
Analyzed
Analyzed - Analysis Complete
Information Disclosure in StorageGRID Metrics Queries Allows Data Exposure
Vulnerability report for CVE-2026-22051, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-04-20
Last updated on: 2026-07-08
Assigner: NetApp, Inc.
Description
Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | storagegrid | to 11.9.0.13 (exc) |
| netapp | storagegrid | From 12.0 (inc) to 12.0.0.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |