Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run unauthorized shell commands across target fabric switches, bypassing command allow-lists and obtaining full administrative switch access. This vulnerability affects all Brocade SANnav versions before 3.0.1a.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Security update provided in Brocade SANnav 3.0.1a
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run unauthorized shell commands across target fabric switches, bypassing command allow-lists and obtaining full administrative switch access. This vulnerability affects all Brocade SANnav versions before 3.0.1a. | |
| Title | Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-09-23T21:33:57.412Z
Reserved: 2026-08-28T19:39:58.088Z
Link: CVE-2026-82369
No data.
Status : Received
Published: 2026-09-23T21:17:03.317
Modified: 2026-09-23T21:17:03.317
Link: CVE-2026-82369
No data.
OpenCVE Enrichment
No data.
Weaknesses