Description
An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries.
Published: 2026-10-08
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: File and directory deletion by an authenticated user with USB management privileges
Action: Immediate Patch
AI Analysis

Impact

An authenticated user with USB management privileges can craft REST API requests that manipulate target paths, allowing deletion of arbitrary files or directories beyond the intended USB mount point boundaries. This flaw permits loss of critical configuration or data files and compromises the integrity of the switch’s local root filesystem, potentially leading to disruption of network operations.

Affected Systems

The issue affects Brocade Fabric OS versions prior to 10.0.1. Any device running a vulnerable Fabric OS build that exposes the USB storage REST API to authenticated users is at risk.

Risk and Exploitability

The vulnerability scores a CVSS base of 5.7, indicating moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit at present. However, the flaw requires authenticated access with specific USB management rights, so exposure risk depends on the security of user credentials and privilege controls. If an attacker gains such credentials, they can delete critical files, potentially causing denial of service or enabling further attacks against the network.

Generated by OpenCVE AI on October 8, 2026 at 04:23 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 10.0.1


OpenCVE Recommended Actions

  • Apply the security update released for Brocade Fabric OS 10.0.1 or later to replace the vulnerable REST API handling of USB operations.
  • Limit USB management privileges to only trusted administrators and deny this capability to general users to reduce the attack surface.
  • Implement monitoring of filesystem changes on the switch and alert on unexpected deletions to detect abuse early.

Generated by OpenCVE AI on October 8, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Title Arbitrary File Deletion via REST API in Brocade Fabric OS
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T03:11:54.902Z

Reserved: 2026-09-21T20:29:06.560Z

Link: CVE-2026-94580

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:18:00.347

Modified: 2026-10-08T04:18:00.347

Link: CVE-2026-94580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')