---
id: CVE-2026-87682
title: >-
  Multiple OS Command Injection vulnerabilities exist in the management
  interface and session processing routines of Brocade Fabric OS versions before
  10.0.1
summary: >-
  Multiple OS Command Injection vulnerabilities exist in the management
  interface and session processing routines of Brocade Fabric OS versions before
  10.0.1. Input processing flaws during remote management connection validation
  and sessio…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T02:16:54.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87682'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39076'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T02:02:29.011Z'
---

## Overview

Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing shell metacharacters to reach internal system execution wrappers. An authenticated user or a compromised directory service account can exploit these vulnerabilities to execute arbitrary operating system commands with elevated privileges on the target device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
