PT-2026-97588 · Brocade · Sannav
CVE-2026-82369
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 3.0.1a
Description
Insufficient input sanitization of shell metacharacters in the CLI scripting component allows authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can execute unauthorized shell commands across target fabric switches, bypassing command allow-lists to obtain full administrative access.
Recommendations
Update Brocade SANnav to version 3.0.1a.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sannav