OS Command Injection Vulnerability in Brocade Fabric OS
CVE-2026-87666

8.6HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87666?

The Brocade Fabric OS versions prior to 9.2.2d and 10.0.0 through 10.0.0a1 are susceptible to an OS command injection vulnerability within the time and zone management subsystem. This flaw occurs when an authenticated user with low-privilege administrative access updates system timezone settings via the REST API. Due to inadequate input sanitization, crafted timezone strings containing shell metacharacters can be submitted, enabling the attacker to execute arbitrary shell commands beyond the restricted environment. This vulnerability underscores the critical need for robust input validation to secure system operations.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.