Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Disable debug level logging in unfixed versions.
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/NTAP-20261009-0026 |
|
History
Fri, 09 Oct 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp trident |
|
| Vendors & Products |
Netapp
Netapp trident |
Fri, 09 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials. | |
| Title | CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident | |
| Weaknesses | CWE-215 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: netapp
Published:
Updated: 2026-10-09T22:02:54.449Z
Reserved: 2026-01-05T22:49:12.527Z
Link: CVE-2026-22061
No data.
Status : Received
Published: 2026-10-09T23:16:54.157
Modified: 2026-10-09T23:16:54.157
Link: CVE-2026-22061
No data.
OpenCVE Enrichment
Updated: 2026-10-09T23:30:13Z
Weaknesses