CVE-2026-22048

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Configurations

No configuration.

History

18 Feb 2026, 14:16

Type Values Removed Values Added
CWE CWE-918
Summary
  • (es) Las versiones de StorageGRID (anteriormente StorageGRID Webscale) anteriores a la 11.9.0.12 y 12.0.0.4 con inicio de sesión único habilitado y configurado para usar Microsoft Entra ID (anteriormente Azure AD) como IdP son susceptibles a una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). Un exploit exitoso podría permitir a un atacante autenticado con pocos privilegios eliminar datos de configuración o denegar el acceso a algunos recursos.

18 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 00:16

Updated : 2026-02-18 17:51


NVD link : CVE-2026-22048

Mitre link : CVE-2026-22048

CVE.ORG link : CVE-2026-22048


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)