Description
An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.
Published: 2026-10-08
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

An authentication bypass flaw resides in the web management interface of Brocade Fabric OS on the MXG610 platform. The vulnerability allows a user without valid credentials to reach an unauthenticated endpoint in the Single Sign‑On workflow and gain full administrative control of the device’s management interface. This flaw exposes the attacker the ability to modify configuration, deploy new services, or redirect traffic, thereby compromising confidentiality, integrity, and availability of the platform.

Affected Systems

The issue affects Brocade Fabric OS versions prior to 9.2.2d. The affected product is the MXG610 series operating under Fabric OS 9.x or earlier, including all builds before 9.2.2d. Updates are available in Fabric OS 9.2.2d and 10.0.1, which correct the authentication weakness.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified with current data. The vulnerability is not listed in the CISA KEV catalog. An attacker who is directly connected to the device’s network—i.e., a network‑adjacent threat—can exploit the unauthenticated SSO endpoint using publicly accessible web requests, making the attack vector nature local or internal.

Generated by OpenCVE AI on October 8, 2026 at 06:22 UTC.

Remediation

Vendor Solution

Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1


OpenCVE Recommended Actions

  • Update the device OS to Brocade Fabric OS 9.2.2d or later 10.0.1 to eliminate the flaw
  • Limit access to the management web interface by configuring firewall rules or VLAN isolation so that only trusted, privileged networks can reach it
  • Enable audit logging and monitor for unexpected SSO or administrative login attempts to detect potential exploitation

Generated by OpenCVE AI on October 8, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Brocade Fabric OS Web Management Interface

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T04:40:08.718Z

Reserved: 2026-09-21T20:30:18.739Z

Link: CVE-2026-94585

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:06.523

Modified: 2026-10-08T05:17:06.523

Link: CVE-2026-94585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel