CVE-2026-5048Medium· 6.1▾ SunlitIn Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5769Medium· 5.6A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM)
CVE-2026-5047High· 8.2A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files
CVE-2026-5049Medium· 6.9A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a
CVE-2026-85423High· 8.6A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0
CVE-2026-85486High· 8.6Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation
CVE-2026-85421High· 8.7A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0