Local Unauthorized Access Vulnerability in Brocade ASCG
CVE-2026-87428

8.4HIGH

Key Information:

Vendor

Brocade

Vendor
CVE Published:
8 October 2026

What is CVE-2026-87428?

A vulnerability exists in Brocade ASCG prior to version 3.5.0 that allows a local unauthorized user on the ASCG virtual machine to issue a request to the SANnav host network namespace. This action can lead to the extraction of stored management credentials for onboarded SANnav instances, which may enable the attacker to compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.

Affected Version(s)

Brocade Active Support Connectivity Gateway 0 < 3.5.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.