CVE-2026-5047: High severity Brocade SANNav vulnerability
A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 2.4.0b - Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.1
Event History
Frequently Asked Questions
Which versions are affected?
Brocade SANnav versions before 2.4.0b and before 3.0.0 are affected.
What access does an attacker need?
The described attack requires an authenticated attacker to obtain access to SANnav log files, including a SANnav supportsave.
What should teams review to determine exposure?
Review access to SANnav log files and supportsave archives, since they may contain encoded passwords and authentication tokens. Anyone who could read those artifacts may be able to access the exposed credentials.