---
id: CVE-2026-87659
title: >-
  A critical authorization bypass vulnerability exists in the Management Server
  handling of Brocade Fabric OS versions before 10.0.1
summary: >-
  A critical authorization bypass vulnerability exists in the Management Server
  handling of Brocade Fabric OS versions before 10.0.1. A compromised switch
  connected to the fabric can transmit crafted inband Fibre Channel
  vendor-unique CT (…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T03:16:35.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87659'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39153'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T03:03:35.548Z'
---

## Overview

A critical authorization bypass vulnerability exists in the Management Server handling of Brocade Fabric OS versions before 10.0.1. A compromised switch connected to the fabric can transmit crafted inband Fibre Channel vendor-unique CT (Common Transport) management requests to bypass administrative authentication. Successful exploitation allows an unauthorized peer switch to execute administrative actions on the target device, including resetting administrative passwords, initiating system reboots, and triggering firmware downloads.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
