CVE-2026-82371

Summary

Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a.

Affected Software

VendorProductVersion RangeStatus
BrocadeSANnavbefore 3.0.1a.affected

Weaknesses

  • CWE-532: CWE-532 Insertion of sensitive information into log file

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References