OS Command Injection Vulnerabilities in Brocade Fabric OS Management Interface
CVE-2026-87682

8.6HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87682?

The management interface and session processing routines of Brocade Fabric OS versions prior to 10.0.1 are susceptible to multiple OS Command Injection vulnerabilities. These arise due to input processing flaws during the validation of remote management connections and session verification for directory-based user accounts. An attacker, whether through an authenticated user account or a compromised directory service account, could exploit these vulnerabilities to inject shell metacharacters. This could facilitate the execution of arbitrary operating system commands with elevated privileges, potentially compromising the target device's integrity and security.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.