CVE-2026-22049: 288 in NETAPP ONTAP 9
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
AI Analysis
Technical Summary
CVE-2026-22049 affects NETAPP ONTAP 9.16.1 when WebAuthn MFA is enabled. The vulnerability involves improper handling of the Relying Party ID, which is a critical parameter in WebAuthn authentication flows. Exploiting this issue could enable an attacker possessing valid user credentials to bypass the MFA protections, effectively reducing the security of the authentication process. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No vendor advisory or patch information is currently available, and no known exploits have been reported in the wild.
Potential Impact
An attacker with valid credentials can bypass the multi-factor authentication configured via WebAuthn, potentially gaining unauthorized access to the system. This undermines the security benefits of MFA and increases the risk of account compromise and subsequent unauthorized actions within the affected ONTAP environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, organizations should consider additional compensating controls such as restricting network access, monitoring for suspicious authentication activity, or temporarily disabling WebAuthn MFA if feasible and safe to do so.
CVE-2026-22049: 288 in NETAPP ONTAP 9
Description
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
CVSS v4.0
Score 8.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-22049 affects NETAPP ONTAP 9.16.1 when WebAuthn MFA is enabled. The vulnerability involves improper handling of the Relying Party ID, which is a critical parameter in WebAuthn authentication flows. Exploiting this issue could enable an attacker possessing valid user credentials to bypass the MFA protections, effectively reducing the security of the authentication process. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No vendor advisory or patch information is currently available, and no known exploits have been reported in the wild.
Potential Impact
An attacker with valid credentials can bypass the multi-factor authentication configured via WebAuthn, potentially gaining unauthorized access to the system. This undermines the security benefits of MFA and increases the risk of account compromise and subsequent unauthorized actions within the affected ONTAP environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, organizations should consider additional compensating controls such as restricting network access, monitoring for suspicious authentication activity, or temporarily disabling WebAuthn MFA if feasible and safe to do so.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- netapp
- Date Reserved
- 2026-01-05T22:47:18.701Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6115199c2644c7f888ff08
Added to database: 07/22/2026, 19:08:09 UTC
Last enriched: 07/30/2026, 01:57:49 UTC
Last updated: 09/05/2026, 00:30:00 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.