CVE-2026-82370

8.6

Brocade · SANnav

Brocade SANnav is vulnerable to unauthenticated remote command injection in its HTTP service, allowing network-adjacent attackers to execute arbitrary CLI commands and container management instructions.

Executive summary

An unauthenticated remote command injection vulnerability in Brocade SANnav allows network-adjacent attackers to achieve unauthorized control over switch configurations and container runtimes.

Vulnerability

This is a command injection flaw (CWE-77) within the SANnav orchestrator HTTP service. The vulnerability allows an unauthenticated, network-adjacent attacker to inject and execute arbitrary administrative commands directly on the switch CLI or within the application container runtime.

Business impact

The ability to execute arbitrary commands on critical infrastructure management software poses a severe risk to organizational operations. With a CVSS score of 8.6, this high-severity vulnerability could lead to the complete compromise of the Fibre Channel fabric, resulting in unauthorized configuration changes, service disruption, or the manipulation of containerized workloads.

Remediation

Immediate Action: Upgrade all instances of Brocade SANnav to version 3.0.1a or later as provided by the vendor.

Proactive Monitoring: Review SANnav access logs for suspicious HTTP requests or unexpected CLI command execution patterns that deviate from established administrative baselines.

Compensating Controls: Restrict network access to the SANnav management interface to trusted management networks only and deploy a WAF to filter potentially malicious command injection payloads.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS severity and the potential for total control over network fabric management, this vulnerability represents a significant risk to environment integrity. Administrators should prioritize the deployment of the 3.0.1a patch immediately to eliminate the attack vector. If patching is not immediately feasible, ensure strict network segmentation is enforced to limit exposure to this management service.

More Brocade CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources