CVE-2026-82369
8.6Brocade · SANnav
Brocade SANnav contains an OS command injection vulnerability in its CLI scripting component, allowing authenticated users to bypass restricted execution contexts and gain administrative switch access.
Executive summary
An OS command injection vulnerability in Brocade SANnav allows authenticated users to achieve full administrative control over managed fabric switches.
Vulnerability
This is an OS command injection flaw (CWE-78) triggered by insufficient sanitization of shell metacharacters within the CLI scripting component. Any authenticated user with command execution permissions can escape restricted contexts to execute unauthorized commands on target switches.
Business impact
The vulnerability poses a severe risk to network infrastructure, as a successful exploit grants an attacker full administrative access to managed fabric switches. Given the CVSS score of 8.6, this flaw could lead to complete compromise of the storage area network, potentially resulting in data exfiltration, service disruption, or unauthorized reconfiguration of critical fabric assets.
Remediation
Immediate Action: Update Brocade SANnav to version 3.0.1a or later immediately to apply the required security patches.
Proactive Monitoring: Review SANnav audit logs and CLI execution history for anomalous command patterns or attempts to invoke shell metacharacters in scripting tasks.
Compensating Controls: Restrict administrative access to the SANnav CLI to the minimum number of necessary users and ensure that network segments containing management interfaces are isolated.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The risk associated with this vulnerability is high due to the potential for full administrative takeover of fabric hardware. IT security teams must prioritize the upgrade to SANnav version 3.0.1a across all affected environments to mitigate the possibility of unauthorized command execution and maintain the integrity of the storage network.
More Brocade CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section