File Manipulation Vulnerability in Brocade Fabric OS by Broadcom
CVE-2026-87685

8.4HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87685?

The Brocade Fabric OS contains an arbitrary file manipulation vulnerability in its WebTools management interface, present in versions prior to 9.2.2d and in 10.0.0 up to version 10.0.0a1. This vulnerability arises from insufficient validation and sanitization of a user-supplied status file path parameter during configuration transfer requests. An authenticated administrative user can exploit this flaw by crafting a malicious status file parameter, potentially allowing the movement of critical system files to a predictable, world-readable temporary directory. Such exploitation can lead to various severe outcomes including persistent Denial of Service, destruction of essential system files, host compromise, and unauthorized access to sensitive data.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.