OS Command Injection Vulnerability in Brocade Fabric OS
CVE-2026-87675

7.3HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87675?

An OS command injection vulnerability in Brocade Fabric OS can occur during configuration download operations. The management daemon inadequately validates configuration parameters, including user-supplied relay host strings and filenames, allowing potential execution of arbitrary commands. This happens due to the local utility's failure to properly sanitize shell metacharacters before processing them in system shell commands. As a result, malicious or compromised configuration files can lead to unauthorized command execution on a remote local switch when an administrator initiates the download.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.