---
id: CVE-2026-87674
title: >-
  A local privilege escalation vulnerability exists in the system logging daemon
  of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1
summary: >-
  A local privilege escalation vulnerability exists in the system logging daemon
  of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1.
  Insufficient access controls on internal inter-process communication (IPC)
  channels a…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:17:53.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87674'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39145'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.124Z'
---

## Overview

A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
