---
id: CVE-2026-94575
title: >-
  A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web
  management framework allows an authenticated, low-privileged user to bypass
  inner Role-Based Access Control (RBAC) checks under specific environmental
  conditions
summary: >-
  A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web
  management framework allows an authenticated, low-privileged user to bypass
  inner Role-Based Access Control (RBAC) checks under specific environmental
  conditions. Succ…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-483
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:18:00.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94575'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39157'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.128Z'
---

## Overview

A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions. Successful exploitation lowers the system authorization mode for the active session context, allowing access to restricted configuration settings intended exclusively for administrative roles.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
