CVE-2026-22048Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-02-18)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-17: 1Mentions · 2026-02-18: 3Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 202-1702-18
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-183
Disclosure1General1Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-22048 StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Az… https://www.cve.org/CVERecord?id=CVE-2026-22048

    Post summary

    The post announces CVE‑2026‑22048, detailing affected StorageGRID versions and SSO configuration, but does not provide a PoC, exploit code, or patch information.

    00010141
    56.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22048 Server-Side Request Forgery in StorageGRID with Microsoft... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22048 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The text announces a new Server‑Side Request Forgery vulnerability (CVE‑2026‑22048) affecting StorageGRID, with a brief description and link to details.

    0000055
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-22048 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Microsoft Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22048 #CVE-2026-22048 #CVE #High #Microsoft #CyberSecurity #InfoSec https://t.co/uByt2EbJft

    Post summary

    The tweet merely announces CVE-2026-22048, notes a 7.1 severity score and high risk for Microsoft, but provides no technical details or mitigation information.

    0000049
    56 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH-severity SSRF in NETAPP StorageGRID (CVE-2026-22048): Authenticated attackers can disrupt or delete configs when SSO with Microsoft Entra ID is enabled. Patch now or disable SSO! https://radar.offseq.com/threat/cve-2026-22048-918-in-netapp-storagegrid-formerly--5c913f90... https://t.co/swsn4KG4fp

    Post summary

    The tweet announces a high‑severity SSRF flaw (CVE‑2026‑22048) in NETAPP StorageGRID that lets authenticated attackers disrupt or delete configurations via SSO with Microsoft Entra ID, and it urges users to apply the patch or disable SSO immediately.

    0000059
    265 followersView on X

Explore more