CVE-2026-82368
Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.
- Published Sep 23, 2026
- CVSS 8.7 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available