CVE-2026-82368

8.7

Brocade · SANnav

Brocade SANnav before 3.0.1a contains an insecure access control flaw allowing local users to execute commands on connected Fabric OS switches with the privileges of the SANnav management user.

Executive summary

A high-severity access control vulnerability in Brocade SANnav allows local users to escalate privileges to the SANnav management context, posing a significant risk to fabric infrastructure integrity.

Vulnerability

This vulnerability involves improper access control (CWE-284) where internal service ports are exposed to local, non-administrative host users. An authenticated local attacker can leverage this exposure to issue unauthorized commands to connected Fabric OS switches using the SANnav management user's security context.

Business impact

The ability for a local user to command Fabric OS switches under the SANnav management context represents a critical security failure, potentially leading to unauthorized configuration changes, service disruption, or full control over the storage area network fabric. With a CVSS score of 8.7, this vulnerability is classified as High and necessitates immediate attention to prevent administrative compromise of sensitive network infrastructure.

Remediation

Immediate Action: Upgrade Brocade SANnav to version 3.0.1a or later as specified in the official Broadcom security advisory.

Proactive Monitoring: Review SANnav access logs for unusual command execution patterns or unauthorized attempts to communicate with backend management services from non-administrative local accounts.

Compensating Controls: Restrict local shell access on the host server running SANnav to only essential administrative personnel to minimize the attack surface until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability and the potential for unauthorized administrative actions on critical fabric infrastructure, organizations must prioritize the update to version 3.0.1a. Applying this patch is the only definitive method to remediate the insecure access control and protect the integrity of the SANnav management environment.

More Brocade CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources