CVE-2026-85490
Received Received - Intake

Path Traversal in Brocade ASCG Before 3.5.0

Vulnerability report for CVE-2026-85490, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entries prior to extraction. An unauthenticated remote attacker capable of sending or intercepting ingested archive files can leverage this flaw to write arbitrary files to restricted locations on the underlying host, potentially leading to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Brocade Active Support Connectivity Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Brocade ASCG versions before 3.5.0. When the system processes support bundle archives from remote endpoints, it does not properly check for path traversal sequences in the archive files. This allows an attacker to write arbitrary files to restricted locations on the host system, which could lead to remote code execution.

Detection Guidance

This vulnerability involves improper handling of support bundle archives in Brocade ASCG before version 3.5.0. Detection requires checking the Brocade ASCG version and inspecting archive processing logs for path traversal attempts. No specific commands are provided in the context.

Impact Analysis

An unauthenticated remote attacker could exploit this flaw to write malicious files to sensitive parts of the system. This may allow them to execute arbitrary code, gain control of the system, or perform further attacks. Systems running vulnerable versions of Brocade ASCG are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access or control of systems handling sensitive data, violating compliance requirements such as GDPR or HIPAA. Unauthorized file writes or code execution may result in data breaches or loss of data integrity, triggering regulatory penalties.

Mitigation Strategies

Immediately upgrade Brocade ASCG to version 3.5.0 or later to address the path traversal flaw in support bundle processing. Ensure all ingested archive files are validated and sanitized before extraction to prevent arbitrary file writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85490. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart