Description
An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authentication bypass and command injection flaw in the inter-switch remote execution service of Brocade Fabric OS. An attacker that can send specially crafted IPC frames to a switch in the fabric can cause the switch to process commands at an elevated level without verifying parameters. This allows the attacker to elevate privileges to root and execute arbitrary commands locally or on other fabric members where remote execution is enabled.

Affected Systems

The flaw affects Brocade Fabric OS versions prior to 9.2.2d and 10.0.0 through 10.0.0a1. The security update is provided for Fabric OS 9.2.2d and 10.0.1.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high risk. The exploit requires that the attacker already be connected to the fabric via a switch, so the threat surface is limited to an attacker with local network access to a fabric device. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Given the possibility of executing root commands, systems in a production fabric should patch immediately or implement mitigations.

Generated by OpenCVE AI on October 8, 2026 at 05:24 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the security update to Brocade Fabric OS 9.2.2d or 10.0.1 to fix the authentication bypass and command injection flaw.
  • Disable the remote execution functionality if it is not required to prevent attacks that rely on the vulnerable IPC frames.
  • Apply network segmentation or restrict access to inter-switch connections so that only trusted switches can communicate via the vulnerable service.

Generated by OpenCVE AI on October 8, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass and Root Command Injection in Brocade Fabric OS Remote Execution Service
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:11:57.889Z

Reserved: 2026-09-08T22:51:12.105Z

Link: CVE-2026-87663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:05.567

Modified: 2026-10-08T05:17:05.567

Link: CVE-2026-87663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing