Database/Control plane, storage & DevOps
NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentials
Impact
An attacker who already has valid credentials sidesteps the WebAuthn second factor because the Relying Party ID is not bound correctly. The hardware-key requirement protecting storage admin logins stops being a barrier.
Who can reach it
A remote attacker in possession of valid ONTAP credentials, against a system running 9.16.1 or later with WebAuthn MFA configured.
What to do
Upgrade to the ONTAP release NetApp names in the advisory. Until then, do not count WebAuthn as the control that stops credential reuse - rotate any password suspected of exposure rather than relying on the second factor.
References
Related entries
- Jenkins: symlinks in tar archives let a job or agent write files anywhere the controller canCVE-2026-33001 · Jenkins controller (.tar/.tar.gz extraction, symlink handling)High
- Apache ActiveMQ: Improper input validation and code injection in the brokerCVE-2026-34197 · Apache ActiveMQHigh
- Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASHCVE-2026-3821 · Supermicro SMASH service (X14DBG-DAP, X14DBI)High
- Ceph RGW: unauthenticated STS token encryption lets any token holder bit-flip themselves to RGW adminCVE-2026-39944 · Ceph RADOS Gateway (STS session token AES-128-CBC handler)High
- MinIO (S3 API, Snowball auto-extract): The Snowball auto-extract path skips signature verification entirely, so anCVE-2026-40344 · MinIO (S3 API, Snowball auto-extract)High
- MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is notCVE-2026-41145 · MinIO (S3 API, unsigned-trailer uploads)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.