Description
An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allows an authenticated, high-privileged remote attacker to execute arbitrary system commands with root permissions. An attacker with administrative privileges to configure SSH known host settings can supply specially crafted parameter values containing shell metacharacters to trigger command execution on the host system.
Published: 2026-10-08
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection in the REST API management interface of Brocade Fabric OS. An attacker who has authenticated, high‑privileged access can supply crafted parameter values containing shell metacharacters. The flaw allows arbitrary system commands to be executed with root permissions, effectively granting full control over the host.

Affected Systems

Affected systems include all Brocade Fabric OS releases prior to 9.2.2d and 10.0.0 through 10.0.0a1. Versions 9.2.2d and 10.0.1 contain the security update that mitigates the issue; earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity and the lack of an EPSS score means exploitation potential cannot be quantified, though the flaw is not listed in CISA KEV. The likely attack path involves an authenticated administrator using the REST API to change SSH known‑host settings; the vulnerability is exploitable remotely from any network location that can reach the API endpoints. Because the affected functionality requires administrative credentials, exploitation is limited to users with high privileges.

Generated by OpenCVE AI on October 8, 2026 at 05:22 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Install Fabric OS 9.2.2d or 10.0.1 security updates to remove the command‑injection flaw.
  • Restrict the ability to modify SSH known‑host settings to only trusted administrators and eliminate unnecessary administrative privileges on the REST API.
  • Monitor REST API traffic for anomalous command‑execution patterns and review logs for suspicious activity.

Generated by OpenCVE AI on October 8, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Injection via Fabric OS REST API
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allows an authenticated, high-privileged remote attacker to execute arbitrary system commands with root permissions. An attacker with administrative privileges to configure SSH known host settings can supply specially crafted parameter values containing shell metacharacters to trigger command execution on the host system.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brocade Fabric Os
cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:20:30.608Z

Reserved: 2026-09-21T20:29:06.560Z

Link: CVE-2026-94581

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:06.393

Modified: 2026-10-08T05:17:06.393

Link: CVE-2026-94581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T05:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')