CVE-2026-5047
Received
Received - Intake
Authentication Token Exposure in Brocade SANnav Logs
Vulnerability report for CVE-2026-5047, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: Brocade Communications Systems, LLC
Description
Description
A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords andΒ authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Brocade | Brocade | SANnav 0 |
| Brocade | Brocade | SANnav 3.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-922 | The product stores sensitive information without properly limiting read or write access by unauthorized actors. |