Database/Control plane, storage & DevOps
NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have no
CVSS 4.3CVE-2026-22052Control plane, storage & DevOpscurated
Impact
An authenticated S3 user lists the contents of directories they have no rights to. Where ONTAP S3 is the object endpoint feeding a training pipeline, that exposes another tenant's dataset layout and object keys.
Who can reach it
Any authenticated S3 client of an ONTAP 9.12.1 or later system with S3 NAS buckets configured.
What to do
Upgrade to the fixed ONTAP release. In the interim, avoid mapping S3 buckets onto NAS paths that are shared across tenants, and prefer per-tenant buckets rooted at separate volumes.
References
Related entries
- GitLab EE: developer-role user can read external status check configuration for a merge requestCVE-2026-4879 · GitLab EE (merge request external status check API)Medium
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingCVE-2026-53437 · Jenkins core (post-login redirect URL validation)Medium
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataCVE-2026-6821 · GitLab EE (merge requests API, IP-based access restrictions)Medium
- Jenkins: symlinks with empty names in agent tar archives write arbitrary files on the controllerCVE-2026-70427 · Jenkins controller (tar and tar.gz extraction of agent-supplied archives)Medium
- Jenkins: path traversal in file parameter names writes arbitrary files on the controller filesystemCVE-2026-70428 · Jenkins controller (path traversal in file parameter names)Medium
- GitLab: developer-role user can replace package file content and hide packages from ownersCVE-2026-7514 · GitLab CE/EE (Generic Package Registry authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.