{"id":"CVE-2026-87674","title":"A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1","summary":"A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels a…","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-78"],"vendor":"Brocade","product":"Fabric OS","affected":["fabric_os < 9.2.2d","fabric_os >= 10.0.0 <= 10.0.0a1"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T04:17:53.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87674","references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39145","label":"sirt@brocade.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-08T04:04:32.124Z","slug":"CVE-2026-87674","body":"## Overview\n\nA local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}