CVE-2026-14442: Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

Published Sep 24, 2026
·
Updated

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.

Affected Software

1 affected component
Broadcom Sannav<3.0.1a

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Brocade SANnav to a version that resolves this vulnerability.

    Fixed in 3.0.1a

Event History

Sep 24, 2026
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the exposed credentials?

A local or authenticated user who can access SANnav application logs or support bundles can view the credentials in cleartext.

2

What activity causes credentials to be logged?

The exposure occurs when scheduled support save jobs or related operational tasks execute. Parameters that may be logged include external server passwords and archive protection keys.

3

What systems or configurations are affected?

SANnav versions before 3.0.1a are affected when the job scheduling component executes the relevant support save or operational tasks. The provided information does not state whether those jobs are enabled by default.

4

What can be done if an upgrade is not immediately possible?

Restrict access to application logs and support bundles to only trusted administrators, since these artifacts may contain cleartext credentials. Review existing logs and support bundles for exposed external server passwords and archive protection keys, then replace any credentials found.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203