---
id: CVE-2026-87667
title: >-
  An argument injection vulnerability exists in the configuration management
  command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0
  through 10.0.0a1
summary: >-
  An argument injection vulnerability exists in the configuration management
  command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0
  through 10.0.0a1. When executing configuration viewing commands with search
  pattern fi…
severity: high
cvss: 8.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'
cwe:
  - CWE-88
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:17:52.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87667'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39151'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.118Z'
---

## Overview

An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filters, the utility fails to sanitize user-supplied search string options before passing them to internal search commands. An authenticated user with low-privilege administrative access can exploit this vulnerability to read arbitrary files on the local operating system, including sensitive configuration files, system password hashes and system secrets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
