Insufficient Input Sanitization in Brocade SANnav CLI Scripting Component
CVE-2026-82369

8.6HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-82369?

The Brocade SANnav CLI scripting component exhibits insufficient input sanitization of shell metacharacters. This vulnerability allows authenticated users to escape restricted execution contexts in managed switches. With the right command execution permissions, an attacker can exploit this weakness to execute unauthorized shell commands across the target fabric switches, effectively bypassing command allow-lists and gaining full administrative access to the switches. This flaw impacts all versions of Brocade SANnav prior to the release of 3.0.1a.

Affected Version(s)

SANnav before 3.0.1a

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.