CVE-2026-85489

In der Brocade ASCG-Administrationsverwaltungskomponente existiert eine Schwachstelle zur Umgehung der Authentifizierung.

Description

An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0.

Metrics

8.7
Source: cna-v4
7.7 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-08 06:39 UTC
CWE-306

Weakness classes (CWE)

  • CWE-306Base

    Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-08 18:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-85489","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-10-08 07:16 UTC· sirt@brocade.com
    • Description: An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0.
    • CVSS V4.0: AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-306
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/85xxx/CVE-2026-85489.json">CVE-2026-85489</a>