CVE-2026-22050
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/01/2026
Last modified:
22/01/2026
Description
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:netapp:ontap:9.16.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p3:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p4:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p5:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p6:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p7:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.16.1:p8:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.17.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:ontap:9.17.1:p1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



