---
id: CVE-2026-5769
title: >-
  A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS
  switch admin password captured in plaintext within a memory swap file on the
  server hosting the Brocade SANnav Virtual Machine (VM)
summary: >-
  A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS
  switch admin password captured in plaintext within a memory swap file on the
  server hosting the Brocade SANnav Virtual Machine (VM). This can happen when
  the S…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-313
vendor: Brocade
product: Brocade SANnav
affected:
  - sannav < 3.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:44.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5769'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/37934'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T07:18:54.841Z'
---

## Overview

A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
