---
id: CVE-2026-94576
title: >-
  An authentication logic and privilege escalation vulnerability exists in the
  account management interface of Brocade Fabric OS versions before 9.2.2d and
  10.0.0 through 10.0.0a1
summary: >-
  An authentication logic and privilege escalation vulnerability exists in the
  account management interface of Brocade Fabric OS versions before 9.2.2d and
  10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can
  bypas…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-187
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T05:17:05.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94576'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39156'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T05:05:36.676Z'
---

## Overview

An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can bypass authorization restrictions intended to prevent modifying another account's access privileges. Exploitation allows a lower-privileged user to assign administrative roles to a target account, leading to localized privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
