Description
Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Published: 2026-09-23
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

An unauthenticated remote command injection flaw exists in the Brocade SANnav orchestrator HTTP service. The vulnerability allows an attacker with network‑adjacent access to inject arbitrary administrative switch CLI commands and container management instructions, potentially altering Fibre Channel fabric switch configurations or manipulating application container runtimes. The weakness aligns with CWE‑77, which represents command injection.

Affected Systems

This issue impacts all Brocade SANnav deployments running versions earlier than 3.0.1a. The affected product is the Brocade SANnav orchestrator. No specific sub‑model or firmware level is listed beyond the general product name and version threshold.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. Although the EPSS score is not available, the absence of a KEV listing suggests limited current exploitation but does not preclude future attacks. Attackers must first reach the orchestrator service, which is typically exposed within the same local area network or managed tenant network. Once the HTTP interface is accessed, the injection can be performed without prior authentication, yielding full administrative privileges over switches and containers.

Generated by OpenCVE AI on September 24, 2026 at 00:20 UTC.

Remediation

Vendor Solution

Security update provided in Brocade SANnav 3.0.1a


OpenCVE Recommended Actions

  • Upgrade Brocade SANnav to version 3.0.1a or later to apply the vendor security update.
  • Restrict network access to the orchestrator HTTP service by configuring firewalls or VLAN isolation, limiting connectivity to trusted management hosts only.
  • Enable and regularly review audit logs for unexpected CLI command activity and container management actions to detect potential exploitation attempts.

Generated by OpenCVE AI on September 24, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade sannav
Vendors & Products Brocade
Brocade sannav

Wed, 23 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.
Title Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-09-23T23:38:48.095Z

Reserved: 2026-08-28T19:39:58.088Z

Link: CVE-2026-82370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T00:17:21.777

Modified: 2026-09-24T00:17:21.777

Link: CVE-2026-82370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T00:30:07Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')