PatchSiren cyber security CVE debrief
CVE-2026-85488 Brocade CVE debrief
CVE-2026-85488 debrief: Brocade ASCG default password vulnerability allows local authenticated users to escalate privileges on affected Open Virtual Appliance deployments. The vulnerability exists due to a well-known default password embedded in a script distributed to every customer. This credential can be discovered by any local authenticated user with read access to the installation path, leading to potential privilege escalation on Open Virtual Appliance deployments where default configuration settings remain in place.
- Vendor
- Brocade
- Product
- Brocade Active Support Connectivity Gateway
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
System administrators and security teams responsible for Brocade ASCG deployments should assess exposure and prioritize remediation. They should verify the installation path and review local user access and authentication settings. Brocade ASCG version 3.5.0 or later is recommended to mitigate this vulnerability.
Why it matters
CVE-2026-85488 is a high-severity vulnerability in Brocade ASCG that allows local authenticated users to escalate privileges due to a well-known default password. Defenders should prioritize verifying and upgrading Brocade ASCG to version 3.5.0 or later, and review local user access and authentication settings.
- Local authenticated users can escalate privileges on affected deployments
- Default password can be discovered by users with read access to the installation path
- Privilege escalation can occur on Open Virtual Appliance deployments with default configuration settings
Technical summary
Brocade ASCG before 3.5.0 contains a well-known default password embedded in a script distributed to every customer, allowing local authenticated users with read access to the installation path to discover the credential and perform privilege escalation on affected Open Virtual Appliance deployments. The vulnerability exists due to a well-known default password embedded in a script distributed to every customer. This credential can be discovered by any local authenticated user with read access to the installation path, leading to potential privilege escalation on Open Virtual Appliance deployments where default configuration settings remain in place.
Defensive priority
Defenders should prioritize verifying and upgrading Brocade ASCG to version 3.5.0 or later, and review local user access and authentication settings.
Recommended defensive actions
- Verify Brocade ASCG version and upgrade to 3.5.0 or later if necessary
- Review local user access and authentication settings
- Monitor system logs for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the Brocade ASCG default password vulnerability. However, additional information on affected deployments and customer impact is limited. Defenders should verify the installation path and review local user access and authentication settings. The well-known default password is a significant risk, as it can be easily discovered by users with read access to the installation path. Brocade ASCG version 3.5.0 or later is recommended to mitigate this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85488 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85488
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85488 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85488
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-85488
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85488.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/38384
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.