{"id":"CVE-2026-82368","title":"Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services","summary":"Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed a…","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-284"],"vendor":"Brocade","product":"SANnav","affected":["SANnav Brocade SANnav versions before 3.0.1a"],"published":"2026-09-23","updated":"2026-09-24","sourceUpdated":"2026-09-24T19:36:39.327","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82368","references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38993","label":"sirt@brocade.com"}],"tags":["nvd","cve.org"],"epss":0.00253,"epssPercentile":0.15054,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T19:33:38.082944Z"},"cvssSource":"cna","ingestedAt":"2026-09-23T19:31:04.468Z","slug":"CVE-2026-82368","body":"## Overview\n\nInsecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}