OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-82370

HIGH · CVSS 8.6 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Brocade SANnav orchestrator is vulnerable to unauthenticated remote command injection, enabling network-adjacent attackers to execute arbitrary administrative commands and manipulate container management instructions. This could lead to unauthorized alterations of Fibre Channel fabric switch configurations and compromise application container runtimes. Organizations using Brocade SANnav versions prior to 3.0.1a should prioritize immediate remediation to mitigate potential impacts on their network infrastructure.

CVE
CVE-2026-82370
Severity
HIGH
CVSS
8.6
EPSS
0.60%

Original NVD Description

Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.