---
id: CVE-2026-85417
title: >-
  Incomplete property masking in the SANnav logging subsystem permits SNMP
  authentication and privacy passwords to be recorded in application logs under
  specific configuration conditions
summary: >-
  Incomplete property masking in the SANnav logging subsystem permits SNMP
  authentication and privacy passwords to be recorded in application logs under
  specific configuration conditions. Individuals with read access to system logs
  or supp…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'
cwe:
  - CWE-532
vendor: Brocade
product: SANnav
affected:
  - SANnav before 3.0.1a
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T16:17:28.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85417'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/39001
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
epss: 0.00191
epssPercentile: 0.07765
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T15:48:54.201840Z'
cvssSource: cna
ingestedAt: '2026-09-25T00:56:54.276Z'
---

## Overview

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
