An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
● Brocade SANnav versions before 3.0.1a
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives. | |
| Title | Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-09-24T21:04:59.555Z
Reserved: 2026-07-01T23:05:42.074Z
Link: CVE-2026-14442
No data.
Status : Received
Published: 2026-09-24T21:17:11.920
Modified: 2026-09-24T21:17:11.920
Link: CVE-2026-14442
No data.
OpenCVE Enrichment
No data.
Weaknesses