Authentication Bypass in Brocade Fabric OS Web Management Interface
CVE-2026-87686
5.3MEDIUM
What is CVE-2026-87686?
A vulnerability allows an attacker to exploit the web server management interface of Brocade Fabric OS, leading to an authentication and access control bypass. This occurs because the web dispatcher routine incorrectly evaluates management VLAN trust decisions using the client-supplied HTTP host header rather than the actual socket transport layer source IP address. As a result, attackers can bypass IP-filtering access control lists, enabling them to access sensitive device metadata, which includes model, serial number, hardware revision, and firmware version without any authentication.
Affected Version(s)
Fabric OS 0 < 10.0.1