Description
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
Published: 2026-10-08
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access to sensitive management data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authorization logic flaw in the Fabric OS REST API gateway that allows an authenticated user to spoof HTTP headers used for access control. Because the gateway solely trusts client‑supplied headers, any user with a valid REST session can forge values and bypass restrictions. This permits low‑privilege users to call internal management endpoints that expose chassis metadata, memory patrolling status, and firmware integrity audit logs, resulting in the disclosure of sensitive operational information.

Affected Systems

Brocade Fabric OS versions prior to 10.0.1 are impacted. The flaw originates in the internal REST API gateway handling of authentication headers, and the security update available in Fabric OS 10.0.1 removes the vulnerable check.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. An attacker requires a valid REST session to craft spoofed headers, so the attack can only be executed once credentialed access is obtained; no public exploits are known, but the simple logic bypass makes the vulnerability straightforward to test internally.

Generated by OpenCVE AI on October 8, 2026 at 04:28 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the security update included in Brocade Fabric OS 10.0.1 to remove the header‑only validation logic.
  • After updating, reboot or restart the fabric switch to ensure the new firmware is active.
  • Verify that REST API requests from authenticated users no longer accept spoofed headers by attempting a test call; if updating is delayed, restrict REST API access to trusted administrators or limit network exposure until the patch can be applied.

Generated by OpenCVE AI on October 8, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Spoofed HTTP Headers in Fabric OS REST API
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:51:42.116Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:36.403

Modified: 2026-10-08T03:16:36.403

Link: CVE-2026-87670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing