Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14442— Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

Quick assessment

Affected
Brocade SANnav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SANnav 的作业调度组件中存在信息泄露漏洞,该漏洞允许敏感凭据以明文形式写入应用程序日志。当执行调度的支持保存作业或相关运维任务时,包括外部服务器密码和归档保护密钥在内的敏感参数会被记录在日志中,且未进行适当的脱敏处理。具有应用程序日志或支持包访问权限的本地用户或已认证用户即可查看这些明文凭据,可能导致对远程备份目标或受保护归档文件的未授权访问。

CVSS 6.9 · Medium EPSS 0.16% · P4
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14442

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a
Source: CVE Program / CVE List V5
Vulnerability Description
An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Brocade SANnav before 3.1.0a -

II. Public POCs for CVE-2026-14442

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14442

请登录查看更多情报信息。

Other References for CVE-2026-14442 (1)

Same Patch Batch · Brocade · 2026-09-24 · 5 CVEs total

CVE-2026-82372 8.5 HIGH Improper handling of sensitive data during IPsec policy creation and modification in Broca
CVE-2026-82371 8.5 HIGH Plaintext exposure of sensitive authentication data in SANnav discovery service log files
CVE-2026-14443 8.4 HIGH Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3
CVE-2026-14441 6.9 MEDIUM Logic flaw in SANnav Java cache key handling object comparison handling

IV. Related Vulnerabilities

V. Comments for CVE-2026-14442

No comments yet


Leave a comment