Input Validation and Output Encoding Vulnerability in Brocade Fabric OS
CVE-2026-87678
6.9MEDIUM
What is CVE-2026-87678?
An input validation and output encoding vulnerability has been identified in the web management interface of Brocade Fabric OS prior to version 10.0.1. This issue arises when configuring Federated Authentication (FA), where the system inadequately sanitizes the Identity Provider (IdP) issuer parameter. As a consequence, an authenticated administrator or an unauthorized attacker capable of providing specially crafted FA configuration files during the import process could inject arbitrary web server directives. This exploitation could disrupt service by preventing the web management daemon from starting and may also compromise web server security controls.
Affected Version(s)
Fabric OS 0 < 10.0.1