CVE-2026-5049: Path Traversal
Published Oct 8, 2026
·Updated
A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended directory.
Affected Software
1 affected component
Brocade SANNav<3.0.0a
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade SANnavto a version that resolves this vulnerability.Fixed in 3.0.1
Event History
Oct 8, 2026
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Brocade SANnav versions before 3.0.0a are affected when the Zone Alias Import flow feature is used.
2
What access does an attacker need to exploit this issue?
An attacker needs local authenticated access. No user interaction is required, and the attack complexity is low.
3
What could an attacker do by exploiting it?
The attacker can write uploaded content outside the directory intended by the Zone Alias Import flow.