Description
An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation via RBAC Bypass
Action: Patch Immediately
AI Analysis

Impact

An Access Control Bypass exists in the Role‑Based Access Control validation engine of Brocade Fabric OS versions prior to 10.0.1. Because the engine misclassifies certain non‑standard action opcodes during permission checks, the system incorrectly grants permission to execute restricted administrative operations. The vulnerability is a classic example of CWE‑269, allowing authenticated users who only have read‑only management privileges to elevate their capabilities and modify fabric configuration or perform other privileged actions, thereby compromising integrity of the network fabric.

Affected Systems

The affected product is Brocade Fabric OS. All releases that precede version 10.0.1 are vulnerable; no newer or patched versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. An attacker must first authenticate to a device using a read‑only account, then send specific management protocol operations that trigger the misclassification. The exploit path requires valid user credentials, but the impact is serious because it allows escalation to full administrative control without additional privileges.

Generated by OpenCVE AI on October 8, 2026 at 02:50 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the security update that releases Brocade Fabric OS 10.0.1 or later
  • Limit or disable read‑only accounts on management interfaces to reduce the exploitation surface
  • Monitor management traffic for abnormal action opcodes to detect potential exploitation attempts

Generated by OpenCVE AI on October 8, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title RBAC Permission Misclassification Enabling Privilege Escalation

Thu, 08 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Description An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T00:57:36.385Z

Reserved: 2026-09-08T22:51:12.186Z

Link: CVE-2026-87681

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T01:16:32.620

Modified: 2026-10-08T01:16:32.620

Link: CVE-2026-87681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T03:45:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management