---
id: CVE-2026-14443
title: >-
  Incomplete log sanitization during bulk IPsec policy collection in Brocade
  SANnav versions before 3.0.1a permit extension switch pre-shared keys to be
  written to system logs
summary: >-
  Incomplete log sanitization during bulk IPsec policy collection in Brocade
  SANnav versions before 3.0.1a permit extension switch pre-shared keys to be
  written to system logs. Individuals with read access to container logs or
  support arch…
severity: high
cvss: 8.4
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-532
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1.a
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:07.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14443'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38998
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T16:27:24.937174Z'
cvssSource: cna
ingestedAt: '2026-09-24T20:51:40.355Z'
---

## Overview

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
