---
id: CVE-2026-82370
title: >-
  Unauthenticated remote command injection in the Brocade SANnav orchestrator
  HTTP service permits network-adjacent attackers to execute arbitrary
  administrative switch CLI commands and issue container management instructions
summary: >-
  Unauthenticated remote command injection in the Brocade SANnav orchestrator
  HTTP service permits network-adjacent attackers to execute arbitrary
  administrative switch CLI commands and issue container management
  instructions. This could a…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-77
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1a
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:17:48.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82370'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38995
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T14:39:00.928550Z'
cvssSource: cna
epss: 0.00605
epssPercentile: 0.46712
ingestedAt: '2026-09-24T00:35:28.610Z'
---

## Overview

Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
