CVE-2026-5048: SQL Injection
Published Oct 8, 2026
·Updated
In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Affected Software
1 affected component
Brocade SANNav<3.0.0a
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.0a - Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.1
Event History
Oct 8, 2026
CVE Published
via MITRE·05:23 AM
Data Sourced
via MITRE·05:23 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Brocade SANnav versions before 3.0.0a are affected. The issue is associated with various external API inventory endpoints.
2
What does an attacker need to exploit this issue?
The attacker must be authenticated. No user interaction is required, and the vulnerable input is in some REST API query parameters.