Remote Command Injection Vulnerability in Brocade SANnav Orchestrator
CVE-2026-82370
8.6HIGH
What is CVE-2026-82370?
An unauthenticated remote command injection flaw exists in the Brocade SANnav orchestrator's HTTP service. This vulnerability allows network-adjacent attackers to execute arbitrary administrative commands on the switch's command-line interface and manipulate operational parameters of container management systems. Exploitation of this vulnerability could lead to unauthorized modifications of Fibre Channel fabric switch configurations or disruption of application container runtimes.
Affected Version(s)
SANnav before 3.0.1a