---
id: CVE-2026-82372
title: >-
  Improper handling of sensitive data during IPsec policy creation and
  modification in Brocade SANnav versions before 3.0.1a results in pre-shared
  keys being recorded in application logs
summary: >-
  Improper handling of sensitive data during IPsec policy creation and
  modification in Brocade SANnav versions before 3.0.1a results in pre-shared
  keys being recorded in application logs. Individuals with read access to
  system log files or…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-532
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:16:34.693'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82372'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38997
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T19:25:24.827937Z'
cvssSource: cna
ingestedAt: '2026-09-24T19:50:30.729Z'
---

## Overview

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or support bundles can view these credentials, leading to the potential exposure of keys used to secure network tunnels.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
