Authorization Bypass Vulnerability in Brocade Fabric OS Management Server
CVE-2026-87659

7.1HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87659?

A serious authorization bypass vulnerability exists in the Management Server component of Brocade Fabric OS prior to version 10.0.1. This flaw allows a compromised switch connected to the fabric to send specially crafted inband Fibre Channel management requests, circumventing administrative authentication processes. Exploiting this vulnerability would enable an unauthorized switch to execute critical administrative actions on the target device, including resetting admin passwords, initiating system reboots, and triggering firmware downloads, thus posing significant security risks.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.