PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14442 Brocade CVE debrief

A local or authenticated user with access to application logs or support bundles can view sensitive credentials due to an information exposure vulnerability in SANnav job scheduling component, potentially leading to unauthorized access. This vulnerability allows sensitive parameters, including external server passwords and archive protection keys, to be logged without proper masking, posing a risk to remote backup targets or protected archives. Defenders should assess exposure and prioritize mitigation, especially for those with access to application logs or support bundles.

Vendor
Brocade
Product
SANnav
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Defenders responsible for SANnav systems, especially those with access to application logs or support bundles, should assess exposure and prioritize mitigation. This includes verifying and restricting access to application logs and support bundles, implementing proper masking for sensitive parameters in logs, and monitoring for unauthorized access to remote backup targets or protected archives. Additionally, defenders should review compensating controls

Why it matters

CVE-2026-14442 is a medium-severity information exposure vulnerability in SANnav that allows sensitive credentials to be written to application logs in plain text, potentially leading to unauthorized access. Defenders should prioritize verifying and mitigating exposure, especially for local or authenticated users with access to application logs or support bundles.

  • Potential unauthorized access to remote backup targets
  • Potential unauthorized access to protected archives
  • Verification of application log and support bundle access controls
  • Prioritization of sensitive parameter masking in logs

Technical summary

The job scheduling component of SANnav writes sensitive credentials to application logs in plain text, allowing local or authenticated users with access to these logs or support bundles to view these cleartext credentials. This vulnerability is caused by the lack of proper masking for sensitive parameters, including external server passwords and archive protection keys, in application logs. As a result, defenders should prioritize verifying and mitigating exposure to application logs and support bundles, especially for local or authenticated users.

Defensive priority

Defenders should prioritize verifying and mitigating exposure to application logs and support bundles, especially for local or authenticated users.

Recommended defensive actions

  • Verify and restrict access to application logs and support bundles
  • Implement proper masking for sensitive parameters in logs
  • Monitor for unauthorized access to remote backup targets or protected archives
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE description and NVD entry provide details on the information exposure vulnerability in SANnav, allowing sensitive credentials to be written to application logs in plain text. The vulnerability is caused by the job scheduling component of SANnav not properly masking sensitive parameters, including external server passwords and archive protection keys, in application logs. This allows local or authenticated users with access to these logs or support bundles to view these cleartext credentials. Defenders should verify and assess

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14442 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14442

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14442 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14442

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38999

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.