---
id: CVE-2026-87685
title: >-
  An arbitrary file manipulation vulnerability exists in the WebTools management
  interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through
  10.0.0a1
summary: >-
  An arbitrary file manipulation vulnerability exists in the WebTools management
  interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through
  10.0.0a1. When processing configuration transfer requests, the application
  fails to p…
severity: high
cvss: 8.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-73
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:17:56.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87685'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39079'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.126Z'
---

## Overview

An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
