Description
An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unprivileged local user can invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations.
Published: 2026-10-08
Score: 7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Denial of Service
Action: Apply Patch
AI Analysis

Impact

An improper file permission and lack of authorization protection in the diagnostic kernel module subsystem of Brocade Fabric OS allows an unprivileged local user to trigger privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations. This flaw can lead to unauthorized control over hardware components and cause service interruptions, affecting the confidentiality of system operations, the integrity of device state, and the availability of the storage fabric.

Affected Systems

Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 are affected. Versions 9.2.2d and 10.0.1 provide a security update that mitigates this vulnerability.

Risk and Exploitability

The CVSS score of 7 indicates a high severity. The EPSS score is not available, making the exploitation likelihood uncertain; however, the flaw is reachable by any local user with no additional privileges. Because the vulnerability is listed in the vendor’s security advisory but not yet in the CISA KEV catalog, it has not yet been confirmed as exploited in the wild. The likely attack vector is local; an attacker would need physical or local network access to the Fabric OS host.

Generated by OpenCVE AI on October 8, 2026 at 05:26 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the Brocade Fabric OS security update to version 9.2.2d or 10.0.1
  • Restrict access to the diagnostic kernel module subsystem, ensuring only privileged users can invoke hardware tests
  • Monitor for unauthorized kernel module operations and hardware reset events to detect potential exploitation attempts

Generated by OpenCVE AI on October 8, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local User Privilege Escalation in Fabric OS Diagnostic Kernel Module
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unprivileged local user can invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations.
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:59:21.404Z

Reserved: 2026-09-08T22:51:12.105Z

Link: CVE-2026-87660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:52.107

Modified: 2026-10-08T04:17:52.107

Link: CVE-2026-87660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource