PatchSiren cyber security CVE debrief
CVE-2026-14442 Brocade CVE debrief
A local or authenticated user with access to application logs or support bundles can view sensitive credentials due to an information exposure vulnerability in SANnav job scheduling component, potentially leading to unauthorized access. This vulnerability allows sensitive parameters, including external server passwords and archive protection keys, to be logged without proper masking, posing a risk to remote backup targets or protected archives. Defenders should assess exposure and prioritize mitigation, especially for those with access to application logs or support bundles.
- Vendor
- Brocade
- Product
- SANnav
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for SANnav systems, especially those with access to application logs or support bundles, should assess exposure and prioritize mitigation. This includes verifying and restricting access to application logs and support bundles, implementing proper masking for sensitive parameters in logs, and monitoring for unauthorized access to remote backup targets or protected archives. Additionally, defenders should review compensating controls
Why it matters
CVE-2026-14442 is a medium-severity information exposure vulnerability in SANnav that allows sensitive credentials to be written to application logs in plain text, potentially leading to unauthorized access. Defenders should prioritize verifying and mitigating exposure, especially for local or authenticated users with access to application logs or support bundles.
- Potential unauthorized access to remote backup targets
- Potential unauthorized access to protected archives
- Verification of application log and support bundle access controls
- Prioritization of sensitive parameter masking in logs
Technical summary
The job scheduling component of SANnav writes sensitive credentials to application logs in plain text, allowing local or authenticated users with access to these logs or support bundles to view these cleartext credentials. This vulnerability is caused by the lack of proper masking for sensitive parameters, including external server passwords and archive protection keys, in application logs. As a result, defenders should prioritize verifying and mitigating exposure to application logs and support bundles, especially for local or authenticated users.
Defensive priority
Defenders should prioritize verifying and mitigating exposure to application logs and support bundles, especially for local or authenticated users.
Recommended defensive actions
- Verify and restrict access to application logs and support bundles
- Implement proper masking for sensitive parameters in logs
- Monitor for unauthorized access to remote backup targets or protected archives
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE description and NVD entry provide details on the information exposure vulnerability in SANnav, allowing sensitive credentials to be written to application logs in plain text. The vulnerability is caused by the job scheduling component of SANnav not properly masking sensitive parameters, including external server passwords and archive protection keys, in application logs. This allows local or authenticated users with access to these logs or support bundles to view these cleartext credentials. Defenders should verify and assess
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14442 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14442
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14442 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14442
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38999
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.