CVE-2026-22049
published 2026-07-22CVE-2026-22049: ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID…
PriorityP261high8.7CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.29%
20.8th percentile
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netapp | ontap_9 | >= 9.16.1 < 9.19.1 | 9.19.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NetApp ONTAP >=9.16.1/9.19.0 Relying Party ID improper authentication
vuldb·2026-07-22·CVSS 8.7
CVE-2026-22049 [HIGH] NetApp ONTAP >=9.16.1/9.19.0 Relying Party ID improper authentication
A vulnerability, which was classified as very critical, was found in NetApp ONTAP >=9.16.1/9.19.0. Impacted is an unknown function of the component Relying Party ID. The manipulation results in improper authentication.
This vulnerability was named CVE-2026-22049. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
GHSA
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could a
ghsa_unreviewed·2026-07-22
CVE-2026-22049 [HIGH] CWE-288 ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could a
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-22
Published