{"id":"CVE-2026-87670","title":"An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway","summary":"An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticat…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-290"],"vendor":"Brocade","product":"Fabric OS","affected":["fabric_os < 10.0.1"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T03:16:36.403","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87670","references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39140","label":"sirt@brocade.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-08T03:03:35.542Z","slug":"CVE-2026-87670","body":"## Overview\n\nAn authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}