Description
An input validation and output encoding vulnerability exists in the web management interface of Brocade Fabric OS versions before 10.0.1. When configuring Federated Authentication (FA), the system fails to sanitize the Identity Provider (IdP) issuer parameter. An authenticated administrator—or an attacker capable of supplying crafted FA configuration files during an import routine—can inject arbitrary web server directives. This can lead to service denial by preventing the web management daemon from starting, or potentially alter web server security controls.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is an input validation and output encoding flaw in the web management interface of Brocade Fabric OS versions prior to 10.0.1. When configuring Federated Authentication, the system does not sanitize the Identity Provider issuer parameter, allowing an attacker to inject arbitrary web server directives. This injection can prevent the web management daemon from starting, resulting in service denial, or can alter the web server’s security controls, potentially weakening protection mechanisms. The weakness is classified as CWE-93: Improper Constraint on Output.

Affected Systems

Brocade Fabric OS, all releases older than version 10.0.1.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator or an attacker who can supply crafted Federated Authentication configuration files during an import routine. The attack vector is thus limited to privileged users with access to the configuration import feature. Given the moderate severity and the requirement for local or privileged access, the risk is considered moderate, but the potential for service disruption makes patching a priority.

Generated by OpenCVE AI on October 8, 2026 at 04:30 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the official security update to Brocade Fabric OS 10.0.1 or later.
  • If an upgrade is not immediately feasible, restrict the import of Federated Authentication configuration files to trusted administrators only and manually review the IdP issuer parameter before acceptance.
  • Consider disabling Federated Authentication or removing custom IdP issuers until the patch can be applied to eliminate the risk of injected web server directives.

Generated by OpenCVE AI on October 8, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Title Input Validation Flaw in Brocade Fabric OS Web Management Allows Injection of Web Server Directives Leading to Denial of Service

Thu, 08 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description An input validation and output encoding vulnerability exists in the web management interface of Brocade Fabric OS versions before 10.0.1. When configuring Federated Authentication (FA), the system fails to sanitize the Identity Provider (IdP) issuer parameter. An authenticated administrator—or an attacker capable of supplying crafted FA configuration files during an import routine—can inject arbitrary web server directives. This can lead to service denial by preventing the web management daemon from starting, or potentially alter web server security controls.
Weaknesses CWE-93
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:45:13.498Z

Reserved: 2026-09-08T22:51:12.167Z

Link: CVE-2026-87678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.093

Modified: 2026-10-08T03:16:37.093

Link: CVE-2026-87678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')