---
id: CVE-2026-87672
title: >-
  An information disclosure vulnerability exists in the SupportLink diagnostic
  collection utilities of Brocade Fabric OS versions before 10.0.1
summary: >-
  An information disclosure vulnerability exists in the SupportLink diagnostic
  collection utilities of Brocade Fabric OS versions before 10.0.1. When
  SupportLink is configured to use an authenticated HTTP proxy, the system
  stores the full …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-532
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T03:16:36.810'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87672'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39142'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T03:03:35.540Z'
---

## Overview

An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support personnel or users with access to file shares where support bundles are stored, can extract these cleartext proxy credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
