---
id: CVE-2026-87687
title: >-
  An authorization and input validation vulnerability exists in Brocade Fabric
  OS versions before 9.2.2d and 10.0.0 through 10.0.0a1
summary: >-
  An authorization and input validation vulnerability exists in Brocade Fabric
  OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user
  with restricted privileges in one Virtual Fabric can exploit this issue by
  submitti…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-88
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:17:56.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87687'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39081'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.125Z'
---

## Overview

An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
