CVE-2026-82370
Received Received - Intake

Unauthenticated Remote Command Injection in Brocade SANnav

Vulnerability report for CVE-2026-82370, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Brocade Communications Systems, LLC

Description

Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brocade sannav to 3.0.1a (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated remote command injection flaw in the Brocade SANnav orchestrator HTTP service. It allows network-adjacent attackers to execute arbitrary administrative switch CLI commands and manage containers without authentication. The issue affects versions before 3.0.1a.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized administrative commands or container management activities on Brocade SANnav systems. Inspect HTTP service logs for unusual POST requests or command execution patterns. Verify if SANnav versions are below 3.0.1a using system commands like 'show version' or checking installed packages.

Impact Analysis

An attacker could alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This may lead to unauthorized access, data breaches, or disruption of network services.

Compliance Impact

This vulnerability allows unauthenticated remote command injection, enabling attackers to execute arbitrary administrative commands on Fibre Channel fabric switches or manipulate container runtimes. Such unauthorized access could lead to unauthorized data access, modification, or deletion, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information.

Mitigation Strategies

Immediately upgrade Brocade SANnav to version 3.0.1a or later. Isolate affected systems from untrusted networks. Review and audit administrative commands and container activities for signs of compromise. Apply network segmentation to limit access to the HTTP service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82370. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart