Impact
The vulnerability lies in Trident's debug logging mechanism, which records unredacted LUKS passphrases and SMB Active Directory credentials when enabled. An authenticated attacker who can read these logs can obtain sensitive passphrases, compromising storage encryption and network authentication. This results in the disclosure of high‑value credentials that could be leveraged for further lateral movement or data exfiltration.
Affected Systems
NetApp Trident, versions v25.02.1 through v26.06.1 are affected. Systems running these releases with debug logging enabled are susceptible.
Risk and Exploitability
The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score is not available and it is not listed in CISA's KEV catalog. An attacker must be authenticated within Trident and have permissions to read debug logs; once those conditions are met, the attacker can view plaintext LUKS passphrases or SMB Active Directory credentials, enabling compromise of data-at-rest encryption and authentication vectors. The lack of a public exploit does not reduce the potential impact, as the disclosed information can be used at any time.
OpenCVE Enrichment