NetApp StorageGRID 11.5+ DoS Vulnerability (Non-Standard Config)
CVE-2026-22056 Published on August 28, 2026

CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-22056 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

What is a File Descriptor Exhaustion Vulnerability?

The software allocates file descriptors or handles on behalf of an actor without imposing any restrictions on how many descriptors can be allocated, in violation of the intended security policy for that actor. This can cause the software to consume all available file descriptors or handles, which can prevent other processes from performing critical file processing operations.

CVE-2026-22056 has been classified to as a File Descriptor Exhaustion vulnerability or weakness.


Products Associated with CVE-2026-22056

Want to know whenever a new CVE is published for NetApp Storagegrid? stack.watch will email you.

 

Affected Versions

NetApp StorageGRID Version 11.5 is affected by CVE-2026-22056