Insecure Access Controls in Brocade SANnav Affect Local Users
CVE-2026-82368
8.7HIGH
What is CVE-2026-82368?
Brocade SANnav versions prior to 3.0.1a exhibit insecure access controls on internal service ports, which can be exploited by local, non-administrative users. This vulnerability allows attackers to communicate with backend management services undetected. By leveraging this exposure, malicious users can transmit commands to the associated Fabric OS switches, effectively operating under the SANnav management user's security context. This situation poses significant risks for data integrity and system management.
Affected Version(s)
SANnav Brocade SANnav versions before 3.0.1a