Description
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
Published: 2026-07-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper handling of the Relying Party ID in WebAuthn multi‑factor authentication on NETAPP ONTAP 9.16.1 and later. The flaw permits an attacker who already possesses valid user credentials to bypass the MFA step, effectively logging in as if the second authentication layer had succeeded. This authentication weakness is identified as CWE‑288 and can result in unauthorized access and privilege escalation.

Affected Systems

NETAPP ONTAP 9 releases 9.16.1 and newer that have WebAuthn MFA configured. Earlier ONTAP versions or configurations without WebAuthn MFA are not affected.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1 % suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Exploitation likely requires only that an attacker has valid credentials; the description infers that an attacker who has obtained or guessed a legitimate username and password could bypass MFA without further privileges or internal access.

Generated by OpenCVE AI on August 3, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ONTAP to a patched release that corrects the Relying Party ID handling flaw, as issued by NETAPP.
  • If a patch is not yet available, disable WebAuthn multi‑factor authentication or reconfigure it to enforce strict Relying Party ID validation until a fix is applied.
  • Apply least‑privilege access controls and monitor authentication logs for signs of MFA bypass, such as repeated successful logins with known valid credentials.

Generated by OpenCVE AI on August 3, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title WebAuthn MFA Bypass due to Improper Relying Party ID Handling

Sun, 02 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Ontap WebAuthn MFA Bypass via Relying Party ID

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Ontap WebAuthn MFA Bypass via Relying Party ID

Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title MFA Bypass via Improper Relying Party ID Handling in ONTAP WebAuthn

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title MFA Bypass via Improper Relying Party ID Handling in ONTAP WebAuthn

Thu, 23 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp ontap 9
Vendors & Products Netapp
Netapp ontap 9

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published:

Updated: 2026-07-25T03:55:53.307Z

Reserved: 2026-01-05T22:47:18.701Z

Link: CVE-2026-22049

cve-icon Vulnrichment

Updated: 2026-07-22T19:08:56.782Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T19:16:59.820

Modified: 2026-07-25T05:16:34.723

Link: CVE-2026-22049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:30:17Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel