StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
History

Tue, 17 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published:

Updated: 2026-02-17T23:01:30.331Z

Reserved: 2026-01-05T22:47:18.701Z

Link: CVE-2026-22048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-18T00:16:18.700

Modified: 2026-02-18T00:16:18.700

Link: CVE-2026-22048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.