Information Disclosure in Brocade Fabric OS Diagnostic Utilities
CVE-2026-87672

6.8MEDIUM

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87672?

An information disclosure vulnerability has been identified in the diagnostic collection utilities of Brocade Fabric OS versions prior to 10.0.1. When configured to utilize an authenticated HTTP proxy, the system intentionally stores the complete URL of the proxy. This design flaw allows individuals, such as support personnel or users with access to shared files where diagnostic bundles are saved, to retrieve sensitive proxy credentials in plaintext form.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.