StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/ntap-20260420-0001 |
|
History
Tue, 21 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Low‑Privilege Information Disclosure via Unrestricted Metrics Queries in NetApp StorageGRID | |
| Weaknesses | CWE-200 CWE-284 |
Mon, 20 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: netapp
Published: 2026-04-20T21:27:36.822Z
Updated: 2026-04-20T21:28:04.859Z
Reserved: 2026-01-05T22:47:18.701Z
Link: CVE-2026-22051
No data.
Status : Received
Published: 2026-04-20T22:16:23.367
Modified: 2026-04-20T22:16:23.367
Link: CVE-2026-22051
No data.