GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have no

CVE-2026-22052Control plane, storage & DevOpscurated

Impact

An authenticated S3 user lists the contents of directories they have no rights to. Where ONTAP S3 is the object endpoint feeding a training pipeline, that exposes another tenant's dataset layout and object keys.

Who can reach it

Any authenticated S3 client of an ONTAP 9.12.1 or later system with S3 NAS buckets configured.

What to do

Upgrade to the fixed ONTAP release. In the interim, avoid mapping S3 buckets onto NAS paths that are shared across tenants, and prefer per-tenant buckets rooted at separate volumes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.