PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-85488 Brocade CVE debrief

CVE-2026-85488 debrief: Brocade ASCG default password vulnerability allows local authenticated users to escalate privileges on affected Open Virtual Appliance deployments. The vulnerability exists due to a well-known default password embedded in a script distributed to every customer. This credential can be discovered by any local authenticated user with read access to the installation path, leading to potential privilege escalation on Open Virtual Appliance deployments where default configuration settings remain in place.

Vendor
Brocade
Product
Brocade Active Support Connectivity Gateway
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

System administrators and security teams responsible for Brocade ASCG deployments should assess exposure and prioritize remediation. They should verify the installation path and review local user access and authentication settings. Brocade ASCG version 3.5.0 or later is recommended to mitigate this vulnerability.

Why it matters

CVE-2026-85488 is a high-severity vulnerability in Brocade ASCG that allows local authenticated users to escalate privileges due to a well-known default password. Defenders should prioritize verifying and upgrading Brocade ASCG to version 3.5.0 or later, and review local user access and authentication settings.

  • Local authenticated users can escalate privileges on affected deployments
  • Default password can be discovered by users with read access to the installation path
  • Privilege escalation can occur on Open Virtual Appliance deployments with default configuration settings

Technical summary

Brocade ASCG before 3.5.0 contains a well-known default password embedded in a script distributed to every customer, allowing local authenticated users with read access to the installation path to discover the credential and perform privilege escalation on affected Open Virtual Appliance deployments. The vulnerability exists due to a well-known default password embedded in a script distributed to every customer. This credential can be discovered by any local authenticated user with read access to the installation path, leading to potential privilege escalation on Open Virtual Appliance deployments where default configuration settings remain in place.

Defensive priority

Defenders should prioritize verifying and upgrading Brocade ASCG to version 3.5.0 or later, and review local user access and authentication settings.

Recommended defensive actions

  • Verify Brocade ASCG version and upgrade to 3.5.0 or later if necessary
  • Review local user access and authentication settings
  • Monitor system logs for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the Brocade ASCG default password vulnerability. However, additional information on affected deployments and customer impact is limited. Defenders should verify the installation path and review local user access and authentication settings. The well-known default password is a significant risk, as it can be easily discovered by users with read access to the installation path. Brocade ASCG version 3.5.0 or later is recommended to mitigate this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-85488 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-85488

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-85488 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85488

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-85488

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85488.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38384

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.