Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass and Root Command Injection in Brocade Fabric OS Remote Execution Service | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled. | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T04:11:57.889Z
Reserved: 2026-09-08T22:51:12.105Z
Link: CVE-2026-87663
No data.
Status : Received
Published: 2026-10-08T05:17:05.567
Modified: 2026-10-08T05:17:05.567
Link: CVE-2026-87663
No data.
OpenCVE Enrichment
Updated: 2026-10-08T05:30:17Z
-
CWE-290
Authentication Bypass by Spoofing