Authentication Bypass and Command Injection in Brocade Fabric OS
CVE-2026-87663
7.1HIGH
What is CVE-2026-87663?
Brocade Fabric OS is impacted by a significant security vulnerability involving authentication bypass and command injection. The flaw exists within the inter-switch remote execution service, where commands processed over the fabric IPC frames can be executed with elevated privileges due to inadequate parameter verification. This means an attacker with access to a single fabric-connected switch can execute arbitrary root commands, potentially affecting other switches within the managed fabric that have remote execution capabilities enabled.
Affected Version(s)
Fabric OS 0 < 9.2.2d
Fabric OS 10.0.0 <= 10.0.0a1