---
id: CVE-2026-94580
title: >-
  An arbitrary file and directory deletion vulnerability exists in the REST API
  management interface handling USB storage operations on Brocade Fabric OS
  versions before 10.0.1
summary: >-
  An arbitrary file and directory deletion vulnerability exists in the REST API
  management interface handling USB storage operations on Brocade Fabric OS
  versions before 10.0.1. An authenticated user possessing USB management
  privileges ca…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 10.0.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:18:00.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94580'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39143'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-08T04:04:32.128Z'
---

## Overview

An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
