Authentication Bypass in Brocade Fabric OS Web Management Interface
CVE-2026-87686

5.3MEDIUM

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-87686?

A vulnerability allows an attacker to exploit the web server management interface of Brocade Fabric OS, leading to an authentication and access control bypass. This occurs because the web dispatcher routine incorrectly evaluates management VLAN trust decisions using the client-supplied HTTP host header rather than the actual socket transport layer source IP address. As a result, attackers can bypass IP-filtering access control lists, enabling them to access sensitive device metadata, which includes model, serial number, hardware revision, and firmware version without any authentication.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.