---
id: CVE-2026-82371
title: >-
  Plaintext exposure of sensitive authentication data in Brocade SANnav
  discovery service log files enables individuals with file read access to
  retrieve administrative switch credentials and active session tokens
summary: >-
  Plaintext exposure of sensitive authentication data in Brocade SANnav
  discovery service log files enables individuals with file read access to
  retrieve administrative switch credentials and active session tokens. An
  attacker with access …
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-532
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1a.
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:17:32.240'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82371'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38996
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T18:37:39.127028Z'
cvssSource: cna
ingestedAt: '2026-09-24T18:49:36.718Z'
epss: 0.00125
epssPercentile: 0.01897
---

## Overview

Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access to system logs or support bundles can leverage exposed authentication details to compromise managed network infrastructure and access active application sessions. This vulnerability affects Brocade SANnav versions before 3.0.1a.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
