CVE-2026-22055

Severity CVSS v4.0:
MEDIUM
Type:
CWE-259 Use of Hard-coded Password
Publication date:
03/06/2026
Last modified:
22/07/2026

Description

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netapp:active_iq_onecollect:2.7.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools