---
id: CVE-2026-87662
title: >-
  Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of
  specific download protocols utilizes unsanitized parameter strings
summary: >-
  Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of
  specific download protocols utilizes unsanitized parameter strings. When
  processing upgrade requests, parameters are converted into system command
  strings and …
severity: high
cvss: 7
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T04:18:13.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87662'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39162'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
epss: 0.00238
epssPercentile: 0.13617
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T15:19:00.618256Z'
cvssSource: cna
ingestedAt: '2026-10-08T05:05:36.681Z'
---

## Overview

Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
