Description
Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges.
Published: 2026-10-08
Score: 7 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when Brocade Fabric OS processes firmware upgrade requests that include unvalidated parameters such as host or file path. These parameters are interpolated into system command strings and executed by the firmware management daemon without removing control or shell metacharacters. Consequently, an attacker can inject and execute arbitrary shell commands with the daemon’s elevated privileges, potentially compromising the entire switch. The weakness corresponds to CWE‑78, reflecting improper command handling that allows injection of executable code.

Affected Systems

Affected vendors include Brocade. The flaw exists in Fabric OS 9.x versions prior to 9.2.2d and in Fabric OS 10.0.0 through 10.0.0a1. Firmware management daemons running on these releases are susceptible to exploitation when upgrade requests are processed.

Risk and Exploitability

The CVSS score of 7 indicates a high‑severity risk. The EPSS score is not reported, so the likelihood of exploitation is unclear but cannot be ruled out. The vulnerability is not listed in the CISA KEV catalog, implying no known exploitation reports as of the current data. Because the attack intrudes through the firmware upgrade interface, the likely vector is remote delivery of a crafted upgrade request over the management network, requiring the attacker to have network access to the device’s management interface.

Generated by OpenCVE AI on October 8, 2026 at 05:25 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the Security Update for Brocade Fabric OS 9.2.2d or 10.0.1 so that the command execution path no longer uses unsanitized parameters.
  • Configure the firmware management daemon to accept upgrade requests only from trusted hosts and enforce authentication or firewall rules that limit access to authorized administrators.
  • Validate and sanitize all fields, such as host and file path, before they are used in command construction to prevent shell injection.
  • Monitor system logs for anomalous command execution patterns and investigate any unexpected activity promptly.

Generated by OpenCVE AI on October 8, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Shell Command Execution via Unsanitized Parameters in Brocade Fabric OS Upgrade Process
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:02:32.204Z

Reserved: 2026-09-08T22:51:12.105Z

Link: CVE-2026-87662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:05.433

Modified: 2026-10-08T05:17:05.433

Link: CVE-2026-87662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')