CVE-2026-22055
Awaiting Analysis
Awaiting Analysis - Queue
Hard-Coded Credentials in Active IQ OneCollect
Publication date: 2026-06-03
Last updated on: 2026-06-04
Assigner: NetApp, Inc.
Description
Description
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netapp | active_iq_onecollect | 2.7.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-259 | The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components. |