File Manipulation Vulnerability in Brocade Fabric OS by Broadcom
CVE-2026-87685
What is CVE-2026-87685?
The Brocade Fabric OS contains an arbitrary file manipulation vulnerability in its WebTools management interface, present in versions prior to 9.2.2d and in 10.0.0 up to version 10.0.0a1. This vulnerability arises from insufficient validation and sanitization of a user-supplied status file path parameter during configuration transfer requests. An authenticated administrative user can exploit this flaw by crafting a malicious status file parameter, potentially allowing the movement of critical system files to a predictable, world-readable temporary directory. Such exploitation can lead to various severe outcomes including persistent Denial of Service, destruction of essential system files, host compromise, and unauthorized access to sensitive data.
Affected Version(s)
Fabric OS 0 < 9.2.2d
Fabric OS 10.0.0 <= 10.0.0a1