Description
Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
Published: 2026-10-09
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Sensitive Credential Disclosure
Action: Disable Debug Logging
AI Analysis

Impact

The vulnerability lies in Trident's debug logging mechanism, which records unredacted LUKS passphrases and SMB Active Directory credentials when enabled. An authenticated attacker who can read these logs can obtain sensitive passphrases, compromising storage encryption and network authentication. This results in the disclosure of high‑value credentials that could be leveraged for further lateral movement or data exfiltration.

Affected Systems

NetApp Trident, versions v25.02.1 through v26.06.1 are affected. Systems running these releases with debug logging enabled are susceptible.

Risk and Exploitability

The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score is not available and it is not listed in CISA's KEV catalog. An attacker must be authenticated within Trident and have permissions to read debug logs; once those conditions are met, the attacker can view plaintext LUKS passphrases or SMB Active Directory credentials, enabling compromise of data-at-rest encryption and authentication vectors. The lack of a public exploit does not reduce the potential impact, as the disclosed information can be used at any time.

Generated by OpenCVE AI on October 9, 2026 at 23:20 UTC.

Remediation

Vendor Workaround

Disable debug level logging in unfixed versions.


OpenCVE Recommended Actions

  • Disable debug level logging in all Trident instances until a patch is available.
  • Delete or securely archive existing debug logs that may contain sensitive credentials.
  • Restrict access to debug logs to only trusted administrative personnel and enforce strict audit controls.

Generated by OpenCVE AI on October 9, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp trident
Vendors & Products Netapp
Netapp trident

Fri, 09 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Description Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
Title CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident
Weaknesses CWE-215
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published:

Updated: 2026-10-09T22:02:54.449Z

Reserved: 2026-01-05T22:49:12.527Z

Link: CVE-2026-22061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T23:16:54.157

Modified: 2026-10-09T23:16:54.157

Link: CVE-2026-22061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T23:30:13Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code