Description
A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation.
Published: 2026-10-08
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Local Priv Escalation
Action: Immediate Patch
AI Analysis

Impact

A local privilege escalation flaw resides in the system logging daemon of Brocade Fabric OS. The daemon accepts logging configuration changes over internal I/O channels that lack proper access controls, letting any local user write a malformed configuration. Because the daemon does not sanitize input before generating its configuration file, an attacker can inject arbitrary directives. When the logging service reloads, those directives are executed with system privileges, allowing the attacker to gain full root rights on the affected device.

Affected Systems

The flaw affects Brocade Fabric OS versions earlier than 9.2.2d and from 10.0.0 through 10.0.0a1. Users running these releases or earlier are at risk, while versions 9.2.2d and later, and 10.0.1, contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 8.5, indicating high severity. The EPSS score is not available, but the flaw requires only local access—any user with local login can exploit it. The flaw is not yet listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. Nevertheless, the combination of high severity, local‑user exploitation, and absence of protection mechanisms creates a significant risk for any system that hosts Brocade Fabric OS and allows local users to interact with the system logging interface.

Generated by OpenCVE AI on October 8, 2026 at 04:50 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the Brocade Fabric OS security update to version 9.2.2d or later, or 10.0.1 or later
  • Restrict local user access to the system logging daemon’s IPC channels to privileged users only
  • Configure the logging service to ignore or validate external configuration reloads before applying changes

Generated by OpenCVE AI on October 8, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Malformed Logging Configuration in Brocade Fabric OS

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:31:26.439Z

Reserved: 2026-09-08T22:51:12.166Z

Link: CVE-2026-87674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:53.370

Modified: 2026-10-08T04:17:53.370

Link: CVE-2026-87674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:00:15Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')