Path Traversal Vulnerability in Brocade ASCG Product
CVE-2026-85490

7.7HIGH

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2026-85490?

Brocade ASCG versions before 3.5.0 are susceptible to a path traversal vulnerability when processing support bundle archives from potentially compromised remote endpoints. The processing mechanism does not adequately sanitize path traversal sequences embedded in these archives before extraction. This flaw enables unauthenticated remote attackers to exploit the vulnerability by sending or intercepting malicious archive files, resulting in the ability to write arbitrary files to restricted directories on the host system. Such actions may ultimately lead to unauthorized remote code execution.

Affected Version(s)

Brocade Active Support Connectivity Gateway 0 < 3.5.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.