Description
In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Published: 2026-10-08
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

The vulnerability is a classic SQL Injection flaw in several REST API query parameters of Brocade SANnav. An attacker who is already authenticated can inject arbitrary SQL statements, potentially reading, modifying, or deleting sensitive data stored in the system’s database. This weakness, classified as CWE-89, presents a moderate risk to confidentiality and integrity, as it allows manipulation of the backend database through crafted inputs.

Affected Systems

The affected product is Brocade SANnav, versions prior to 3.0.0a. All deployments running 3.0.0a or 3.0.1 include the security fix and are no longer vulnerable.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The flaw requires the attacker to be authenticated and to access the exposed REST API endpoints, making it likely to be exploited in environments where API credentials are compromised or poorly secured. The impact is limited to systems that expose these APIs and store critical data accessible via the backend database.

Generated by OpenCVE AI on October 8, 2026 at 06:20 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 3.0.0a and 3.0.1


OpenCVE Recommended Actions

  • Apply the security update to SANnav 3.0.0a or later.
  • Restrict access to the REST API by enabling network-level controls or firewall rules.
  • Validate and sanitize all query parameters on the server side to prevent injection of SQL code.

Generated by OpenCVE AI on October 8, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in Brocade SANnav REST API

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T05:23:56.926Z

Reserved: 2026-03-27T16:45:35.378Z

Link: CVE-2026-5048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:43.273

Modified: 2026-10-08T06:16:43.273

Link: CVE-2026-5048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')