---
id: CVE-2026-5047
title: "A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and\_ authentication tokens in log files"
summary: "A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and\_ authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supports…"
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'
cwe:
  - CWE-922
vendor: Brocade
product: Brocade SANnav
affected:
  - sannav < 2.4.0b
  - sannav 3.0.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:42.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5047'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/37933'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T06:06:55.456Z'
---

## Overview

A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
