Description
An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access.
Published: 2026-10-08
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Cross-Fabric Access via authorization bypass
Action: Patch Immediately
AI Analysis

Impact

An authentication bypass coupled with inadequate input validation in Brocade Fabric OS permits a user who has been granted only limited privileges within a single Virtual Fabric to issue a specially crafted request that references another fabric identifier. The vulnerability, categorized as CWE-88, enables the attacker to carry out unauthorized operations across fabrics and to read configuration information that should be inaccessible. The affected user can effectively gain the same capabilities and visibility as a higher‑privileged administrator within the target fabric.

Affected Systems

The flaw impacts all versions of Brocade Fabric OS prior to 9.2.2d and 10.0.0 through 10.0.0a1. Any deployment running one of these releases is susceptible, regardless of the number of virtual fabrics configured.

Risk and Exploitability

The CVSS score of 8.5 indicates a high‑severity exploitation risk. While the EPSS score is not reported, the lack of a KEV listing suggests no publicly known exploits yet. The attack requires the attacker to be authenticated with restricted privileges in a virtual fabric, after which a crafted request can be sent to trigger the cross‑fabric access. Given the absence of a widely known exploit, the likelihood of immediate compromise is moderate, but the potential impact warrants timely remediation.

Generated by OpenCVE AI on October 8, 2026 at 04:51 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the security update to Brocade Fabric OS 9.2.2d or 10.0.1 to eliminate the vulnerability.
  • Review and tighten user permissions so that only needed virtual fabric privileges are granted, and remove any cross‑fabric authorization scopes that are unnecessary.
  • If an immediate upgrade is not feasible, restrict network access to the management interfaces and monitor for suspicious request patterns that reference fabric identifiers not belonging to the user’s domain.

Generated by OpenCVE AI on October 8, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
Title Fabric OS Cross‑Fabric Permission Bypass

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access.
Weaknesses CWE-88
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:26:46.448Z

Reserved: 2026-09-08T22:51:12.186Z

Link: CVE-2026-87687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:56.360

Modified: 2026-10-08T04:17:56.360

Link: CVE-2026-87687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:00:15Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')