Command Injection Vulnerability in Brocade Fabric by Broadcom
CVE-2026-87662

7HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87662?

A vulnerability exists in Brocade Fabric due to improper handling of specific download protocols. This issue arises from the lack of sanitization for parameter strings during upgrade requests. When these unsanitized parameters are processed, they can be converted into system command strings that the firmware management daemon executes with elevated privileges. This oversight allows an attacker to inject arbitrary shell commands, potentially compromising the integrity and security of the affected systems.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.