Description
An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.
Published: 2026-10-08
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution (root privileges)
Action: Immediate Patch
AI Analysis

Impact

An OS command injection flaw exists in the PAM session cleanup routines of Brocade Fabric OS. If an authenticated user authenticates via an external directory or AAA service and their username or profile identifier contains shell metacharacters, the service will inject those characters into an OS command executed during SSH session termination. This results in arbitrary command execution with root privileges when the remote SSH session closes.

Affected Systems

Brocade Fabric OS versions prior to 9.2.2d and the 10.0.0 through 10.0.0a1 releases are affected. Older 9.x releases before 9.2.2d also have the vulnerability.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user to create or modify a username or profile identifier that includes shell metacharacters, typically through the external directory or AAA service. When the user logs out via SSH, the PAM cleanup routine executes the malformed command as root, granting the attacker arbitrary root‑level command execution on the Fabric OS host.

Generated by OpenCVE AI on October 8, 2026 at 06:24 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Apply the security update to Brocade Fabric OS 9.2.2d or 10.0.1 as issued by the vendor.
  • If upgrading is not immediately possible, enforce sanitization or validation of shell metacharacters in usernames and profile identifiers in the external directory or AAA service to prevent injection.
  • When possible, disable or restrict SSH session termination triggers that invoke the PAM cleanup routine to reduce the attack surface.
  • Review and tighten external directory account creation policies to disallow shell metacharacters in identifiers.

Generated by OpenCVE AI on October 8, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Brocade Fabric OS SSH Session Cleanup

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:35:58.198Z

Reserved: 2026-09-21T20:29:06.560Z

Link: CVE-2026-94579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:06.247

Modified: 2026-10-08T05:17:06.247

Link: CVE-2026-94579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')