Input Validation and Output Encoding Vulnerability in Brocade Fabric OS
CVE-2026-87678

6.9MEDIUM

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87678?

An input validation and output encoding vulnerability has been identified in the web management interface of Brocade Fabric OS prior to version 10.0.1. This issue arises when configuring Federated Authentication (FA), where the system inadequately sanitizes the Identity Provider (IdP) issuer parameter. As a consequence, an authenticated administrator or an unauthorized attacker capable of providing specially crafted FA configuration files during the import process could inject arbitrary web server directives. This exploitation could disrupt service by preventing the web management daemon from starting and may also compromise web server security controls.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.