Description
A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions. Successful exploitation lowers the system authorization mode for the active session context, allowing access to restricted configuration settings intended exclusively for administrative roles.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation via RBAC Bypass
Action: Apply Patch
AI Analysis

Impact

A logic vulnerability in the web management framework of Brocade Fabric OS allows an authenticated user with low privileges to bypass internal Role-Based Access Control (RBAC) checks under certain environmental conditions. By exploiting this flaw, the attacker can lower the authorization mode for the active session and gain access to configuration settings that are normally restricted to administrative roles. The CVSS score of 6.9 reflects that the vulnerability can lead to unauthorized configuration changes, impacting confidentiality, integrity, and availability of the fabric management environment.

Affected Systems

The flaw exists in all Brocade Fabric OS releases prior to version 10.0.1. Only the 10.0.1 release or later contains the remediation that eliminates the RBAC bypass logic. Critical systems running older Fabric OS should be verified for this vulnerability.

Risk and Exploitability

The vulnerability requires the attacker to be authenticated and possess a low‑privilege account; it does not provide remote code execution. The impact is limited to elevated privileges within the management session, but can change critical configuration settings. Because no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain; however, the attack vector is internal or via the web interface, making it relevant to environments where web management access is granted to non‑admin users. Rapid patching is therefore recommended to prevent potential privilege escalation.

Generated by OpenCVE AI on October 8, 2026 at 04:24 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Update Fabric OS to version 10.0.1 or later to eliminate the RBAC bypass logic
  • Restrict web management access to trusted administrators and remove low‑privileged accounts from the web interface
  • Monitor configuration changes in Fabric OS for unauthorized modifications after applying the fix

Generated by OpenCVE AI on October 8, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via RBAC Bypass in Brocade Fabric OS Web Management
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions. Successful exploitation lowers the system authorization mode for the active session context, allowing access to restricted configuration settings intended exclusively for administrative roles.
Weaknesses CWE-483
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:09:26.444Z

Reserved: 2026-09-21T20:29:06.560Z

Link: CVE-2026-94575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:18:00.023

Modified: 2026-10-08T04:18:00.023

Link: CVE-2026-94575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-483

    Incorrect Block Delimitation