---
id: CVE-2026-94578
title: >-
  Brocade Fabric OS versions before 10.0.1 contain an authorization logic
  vulnerability in the AAA (Authentication, Authorization, and Accounting)
  integration framework allows remote authenticated users to gain
  root-equivalent chassis acce…
summary: >-
  Brocade Fabric OS versions before 10.0.1 contain an authorization logic
  vulnerability in the AAA (Authentication, Authorization, and Accounting)
  integration framework allows remote authenticated users to gain
  root-equivalent chassis acce…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-269
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T03:16:37.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94578'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39150'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T03:03:35.548Z'
---

## Overview

Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
