CVE-2026-87667High· 8.4▾ TwilightAn argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern fi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filters, the utility fails to sanitize user-supplied search string options before passing them to internal search commands. An authenticated user with low-privilege administrative access can exploit this vulnerability to read arbitrary files on the local operating system, including sensitive configuration files, system password hashes and system secrets.
fabric_os < 9.2.2dfabric_os >= 10.0.0 <= 10.0.0a1Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87687High· 8.5An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1
CVE-2026-94580Medium· 5.7An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1
CVE-2026-94575Medium· 6.9A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions
CVE-2026-87688High· 8.5An input validation vulnerability exists in the security certificate management component of the Brocade Fabric OS administrative management API
CVE-2026-94584Low· 2.1A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1
CVE-2026-87685High· 8.4An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1