Description
Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context.
Published: 2026-10-08
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in the REST API management component of Brocade Fabric OS. When the service processes API requests, it does not correctly check array sizes or string lengths against internal buffer limits, allowing an authenticated attacker with REST API access to send oversized payloads. This can corrupt the execution stack, potentially causing a denial‑of‑service through a daemon crash or enabling the attacker to execute arbitrary code within the management process context. The flaw aligns with CWE‑121, indicating an improper handling of buffer bounds.

Affected Systems

Brocade Fabric OS versions prior to 10.0.1 are affected. This includes all deployments running Fabric OS below the 10.0.1 release, regardless of configuration or additional modules. The advisory does not specify narrower version ranges, so the entire pre‑10.0.1 set should be considered vulnerable.

Risk and Exploitability

The CVSS score of 8.6 marks the issue as high severity. While the EPSS score is not available, the potential for arbitrary code execution and the requirement of only authenticated REST API access make exploitation plausible in environments where administrators or malicious users can access the API. The vulnerability is not listed in the CISA KEV catalog, but its severity and exploitability still warrant immediate attention. An attacker would typically proceed by authenticating to the REST API, crafting a request with excessive array or string parameters, and transmitting it to trigger the overflow. Successful exploitation could lead to service disruption or full compromise of the management process.

Generated by OpenCVE AI on October 8, 2026 at 02:22 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the security update for Brocade Fabric OS 10.0.1 or later to eliminate the buffer overflow.
  • If an immediate upgrade is not possible, restrict REST API access to a minimal set of trusted administrative accounts and enforce strict network segmentation to limit exposure.
  • Enhance monitoring of the REST API and Fabric OS daemon for abnormal crashes or memory corruption events, and review audit logs for suspicious request patterns.

Generated by OpenCVE AI on October 8, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Brocade Fabric OS REST API Allows Denial of Service and Code Execution
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context.
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T01:07:17.780Z

Reserved: 2026-09-08T22:51:12.186Z

Link: CVE-2026-87683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T02:16:54.563

Modified: 2026-10-08T02:16:54.563

Link: CVE-2026-87683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T02:30:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow