Description
An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage.
Published: 2026-10-08
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Host Compromise
Action: Immediate Patch
AI Analysis

Impact

An authenticated administrative user can submit a crafted status file path to the Fabric OS WebTools interface, causing the system to move an arbitrary file to a predictable, world‑readable temporary location. This flaw permits persistent denial of service, deliberate deletion of critical system files, host compromise, or leakage of sensitive data by granting the attacker control over file placement and visibility.

Affected Systems

The vulnerability is present in Brocade Fabric OS versions before 9.2.2d and from 10.0.0 through 10.0.0a1, affecting only installations that expose the WebTools management interface. The known fix is provided in Fabric OS 9.2.2d and 10.0.1.

Risk and Exploitability

The flaw carries a CVSS score of 8.4 and currently has no EPSS data, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator, after which the attacker can move files to world‑readable directories, facilitating denial of service, file corruption, or information disclosure. The high severity and privileged‑authentication prerequisite place significant risk on environments where admin interfaces are exposed.

Generated by OpenCVE AI on October 8, 2026 at 04:22 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the published security update in Brocade Fabric OS 9.2.2d or 10.0.1.
  • Restrict access to the WebTools interface to trusted administrators and enforce least privilege.
  • If an immediate update is not available, isolate the affected WebTools service from the rest of the network to reduce exposure.

Generated by OpenCVE AI on October 8, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Title Arbitrary File Manipulation in Brocade Fabric OS WebTools Allows Admin to Move System Files to World-Readable Locations
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage.
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:24:23.925Z

Reserved: 2026-09-08T22:51:12.186Z

Link: CVE-2026-87685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:56.097

Modified: 2026-10-08T04:17:56.097

Link: CVE-2026-87685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-73

    External Control of File Name or Path