CVE-2026-22050

ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:ontap:9.16.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p1:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p2:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p3:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p4:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p5:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p6:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p7:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p8:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.17.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.17.1:p1:*:*:*:*:*:*

History

22 Jan 2026, 17:58

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:ontap:9.16.1:p2:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p8:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p6:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p4:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p3:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.17.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.17.1:p1:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p5:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p1:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.16.1:p7:*:*:*:*:*:*
First Time Netapp ontap
Netapp
References () https://security.netapp.com/advisory/NTAP-20260112-0001 - () https://security.netapp.com/advisory/NTAP-20260112-0001 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

13 Jan 2026, 18:16

Type Values Removed Values Added
CWE CWE-639

12 Jan 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 18:15

Updated : 2026-01-22 17:58


NVD link : CVE-2026-22050

Mitre link : CVE-2026-22050

CVE.ORG link : CVE-2026-22050


JSON object : View

Products Affected

netapp

  • ontap
CWE
CWE-639

Authorization Bypass Through User-Controlled Key