---
id: CVE-2026-94577
title: >-
  A privilege escalation vulnerability exists in the internal Command-Line
  Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions
  before 9.2.2d and 10.0.0 through 10.0.0a1
summary: >-
  A privilege escalation vulnerability exists in the internal Command-Line
  Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions
  before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local
  process tha…
severity: high
cvss: 7.3
cvssVector: 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-15
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T04:18:14.737'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94577'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39154'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
epss: 0.00102
epssPercentile: 0.00862
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T15:18:56.735745Z'
cvssSource: cna
ingestedAt: '2026-10-08T05:05:36.681Z'
---

## Overview

A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access Control (RBAC) validation checks. Successful exploitation allows an attacker to elevate privileges to root

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
