---
id: CVE-2026-82369
title: >-
  Insufficient input sanitization of shell metacharacters in the Brocade SANnav
  CLI scripting component permits authenticated users to break out of restricted
  execution contexts on managed switches
summary: >-
  Insufficient input sanitization of shell metacharacters in the Brocade SANnav
  CLI scripting component permits authenticated users to break out of restricted
  execution contexts on managed switches. An attacker with command execution
  permi…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1a
published: '2026-09-23'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:17:48.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82369'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38994
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T14:09:40.089129Z'
cvssSource: cna
epss: 0.00512
epssPercentile: 0.41099
ingestedAt: '2026-09-23T21:33:13.538Z'
---

## Overview

Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissions can leverage this flaw to run unauthorized shell commands across target fabric switches, bypassing command allow-lists and obtaining full administrative switch access. This vulnerability affects all Brocade SANnav versions before 3.0.1a.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
