---
id: CVE-2026-22051
title: >-
  StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and
  12.0.0.6 are susceptible to a Information Disclosure vulnerability
summary: >-
  StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and
  12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful
  exploit could allow an authenticated attacker with low privileges to run
  arbitrary…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: netapp
product: storagegrid
affected:
  - storagegrid < 11.9.0.13
  - 'storagegrid >= 12.0, < 12.0.0.6'
patched:
  - storagegrid 12.0.0.6
published: '2026-04-20'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22051'
references:
  - url: 'https://security.netapp.com/advisory/ntap-20260420-0001'
    label: security-alert@netapp.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07104
ingestedAt: '2026-07-08T03:46:38.656Z'
---

## Overview

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.

## Affected

- `storagegrid < 11.9.0.13`
- `storagegrid >= 12.0, < 12.0.0.6`

## Remediation

Upgrade past the affected range:

- `storagegrid 12.0.0.6`
