PatchSiren cyber security CVE debrief
CVE-2026-5048 Brocade CVE debrief
CVE-2026-5048 is an SQL Injection vulnerability in Brocade SANnav before 3.0.0a, allowing an authenticated attacker to inject malicious data into some REST API query parameters. Defenders should assess exposure, prioritize remediation, and verify inventory for vulnerable versions. This vulnerability has potential data integrity impact and requires verification of Brocade SANnav versions and exposure. The attack requires authentication, which reduces immediate risk but still necessitates prompt action. Monitoring and incident response planning are recommended. The CVE record and source item provide details on the SQL Injection vulnerability in Brocade SANnav. The vendor, Brocade, is
- Vendor
- Brocade
- Product
- Brocade SANnav
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders managing Brocade SANnav systems, particularly those with external API inventories exposed, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-5048 is an SQL Injection vulnerability in Brocade SANnav before 3.0.0a. Defenders managing Brocade SANnav systems should assess exposure, prioritize remediation, and verify inventory for vulnerable versions due to potential data impact and the need for version verification.
- Potential data integrity impact due to SQL Injection
- Requires verification of Brocade SANnav versions and exposure
- Authenticated attack requirement reduces immediate risk but still necessitates prompt action
- Monitoring and incident response planning recommended
Technical summary
The vulnerability exists in various external API inventories of Brocade SANnav before 3.0.0a, allowing an authenticated attacker to inject malicious data into some REST API query parameters. This SQL Injection vulnerability has a medium priority for inventory checks and remediation due to the authenticated attack requirement and potential data impact. Defenders managing Brocade SANnav systems, particularly those with external API inventories exposed, should assess exposure and prioritize remediation. The NVD entry is currently empty, and supplemental source
Defensive priority
Medium priority for inventory checks and remediation due to authenticated attack requirement and potential data impact.
Recommended defensive actions
- Inventory check: Verify Brocade SANnav versions are 3.0.0a or later.
- Remediation: Upgrade to Brocade SANnav 3.0.0a or later.
- Monitoring: Implement monitoring for potential SQL Injection attempts.
Evidence notes
The CVE record and source item provide details on the SQL Injection vulnerability in Brocade SANnav. The vendor, Brocade, is the canonical source. The NVD entry is currently empty.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5048 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5048
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5048 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5048
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-5048
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/5xxx/CVE-2026-5048.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/37932
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.