---
id: CVE-2026-94586
title: >-
  A command injection vulnerability exists in the WebTools administrative
  interface handling configuration download or file transfer operations of
  Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1
summary: >-
  A command injection vulnerability exists in the WebTools administrative
  interface handling configuration download or file transfer operations of
  Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An
  authenticated user …
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: Brocade
product: Fabric OS
affected:
  - fabric_os < 9.2.2d
  - fabric_os >= 10.0.0 <= 10.0.0a1
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T04:18:15.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94586'
references:
  - url: 'https://support.broadcom.com/external/content/SecurityAdvisories/0/39135'
    label: sirt@brocade.com
tags:
  - nvd
  - cve.org
epss: 0.01248
epssPercentile: 0.68425
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T15:18:53.930353Z'
cvssSource: cna
ingestedAt: '2026-10-08T05:05:36.680Z'
---

## Overview

A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can supply malicious parameter strings to execute arbitrary shell commands on the switch with root privileges

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
