Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14441— Logic flaw in SANnav Java cache key handling object comparison handling

Quick assessment

Affected
Brocade SANnav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Java 缓存键处理中对象比较逻辑存在缺陷,可能导致在处理特定用户账户结构时出现标识符解析不当的问题。该问题已通过更新内部比较例程得到修复,以确保准确的对象评估,并防止潜在的身份不匹配情况。

CVSS 6.9 · Medium EPSS 0.36% · P27
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14441

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Logic flaw in SANnav Java cache key handling object comparison handling
Source: CVE Program / CVE List V5
Vulnerability Description
A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用错误要素进行比较
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Brocade SANnav before 3.0.1a -

II. Public POCs for CVE-2026-14441

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14441

请登录查看更多情报信息。

Other References for CVE-2026-14441 (1)

Same Patch Batch · Brocade · 2026-09-24 · 5 CVEs total

CVE-2026-82372 8.5 HIGH Improper handling of sensitive data during IPsec policy creation and modification in Broca
CVE-2026-82371 8.5 HIGH Plaintext exposure of sensitive authentication data in SANnav discovery service log files
CVE-2026-14443 8.4 HIGH Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3
CVE-2026-14442 6.9 MEDIUM Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

IV. Related Vulnerabilities

V. Comments for CVE-2026-14441

No comments yet


Leave a comment