Privilege Escalation Vulnerability in Brocade Open Virtual Appliance
CVE-2026-85488

7HIGH

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2026-85488?

A vulnerability exists in Brocade's Open Virtual Appliance due to the inclusion of a default password in a publicly accessible script. Local authenticated users with read access to the installation directory can easily identify this credential. If default configuration settings are not altered, this can lead to unauthorized privilege escalation on the affected deployments, potentially compromising the security of the system.

Affected Version(s)

Brocade Active Support Connectivity Gateway 0 < 3.5.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.