Local Privilege Escalation in Brocade Fabric OS Logging Service
CVE-2026-87674

8.5HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87674?

A local privilege escalation vulnerability affects Brocade Fabric OS due to inadequate access controls on inter-process communication channels. Unprivileged local users can exploit this weakness by submitting malformed logging configurations, leading to improper input sanitization during configuration file creation. This allows for injection of arbitrary directives that execute with elevated privileges upon reload of the logging service, enabling an attacker to gain unauthorized access.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.