CVE-2026-85417

Severity CVSS v4.0:
MEDIUM
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
25/09/2026
Last modified:
25/09/2026

Description

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or support bundles can retrieve these credentials, leading to unauthorized read or management access to monitored switch environments