CVE-2026-94578High· 7.5▾ TwilightBrocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis acce…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.
fabric_os < 10.0.1Security update is provided in Brocade Fabric OS 10.0.1
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87681High· 7.1An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1
CVE-2026-87684High· 8.7A stack-based buffer overflow vulnerability exists in the SNMP daemon request handling of Brocade Fabric versions before 10.0.1
CVE-2026-87671High· 7.1An out-of-bounds memory read vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1
CVE-2026-87659High· 7.1A critical authorization bypass vulnerability exists in the Management Server handling of Brocade Fabric OS versions before 10.0.1
CVE-2026-87686Medium· 5.3An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1
CVE-2026-87676Medium· 6.9A stack-based buffer overflow vulnerability exists in the security library component of Brocade Fabric OS versions before 10.0.1