OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-82368

HIGH · CVSS 8.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Insecure access controls in Brocade SANnav versions prior to 3.0.1a enable local, non-administrative users to interact directly with backend management services, potentially allowing them to send commands to Fabric OS switches. This vulnerability poses a significant risk as it can be exploited by local attackers to manipulate network configurations under the SANnav management user's privileges. Organizations using affected versions should prioritize remediation to mitigate unauthorized access and potential disruption to their storage area networks.

CVE
CVE-2026-82368
Severity
HIGH
CVSS
8.7
EPSS
0.25%

Original NVD Description

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.