Description
An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated information disclosure via authentication bypass
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the web dispatcher routine of Brocade Fabric OS, where the system incorrectly uses the client‑supplied HTTP Host header instead of the source IP when determining internal management VLAN trust. This oversight enables an attacker to bypass ACLs on the management interface and pull device metadata—including model, serial number, hardware revision, and firmware version—without any authentication. Once an adversary gains this device information, they can target the appliance for further attacks.

Affected Systems

Devices running Brocade Fabric OS versions earlier than 10.0.1 are impacted. The vulnerability is in the web server management interface and applies to any deployment that relies on the default internal management VLAN trust settings.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. Exploitation requires a crafted HTTP request with a manipulated Host header sent to the management web server, and no authentication is necessary. Although the attack surface is limited to the management interface, the ability to obtain device details without authentication poses a significant risk for targeted post‑exploitation efforts.

Generated by OpenCVE AI on October 8, 2026 at 03:21 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Update to Brocade Fabric OS 10.0.1 or newer, which corrects the host header validation flaw.
  • Restrict access to the management web interface to trusted IP ranges or VPN connections and enforce strict IP‑based ACLs on the management VLAN.
  • If patching cannot occur immediately, disable or block remote web‑management services on untrusted networks until the update is installed.

Generated by OpenCVE AI on October 8, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Title Brocade Fabric OS Authentication Bypass via HTTP Host Header
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T02:31:52.669Z

Reserved: 2026-09-08T22:51:12.186Z

Link: CVE-2026-87686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.390

Modified: 2026-10-08T03:16:37.390

Link: CVE-2026-87686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T03:30:16Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing