Authorization Logic Vulnerability in Brocade Fabric OS by Broadcom
CVE-2026-94578

7.5HIGH

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-94578?

Brocade Fabric OS prior to version 10.0.1 has an authorization logic flaw linked to the AAA (Authentication, Authorization, and Accounting) integration framework. This flaw permits remote authenticated users to gain elevated access privileges on the chassis by exploiting crafted Vendor-Specific Attributes (VSAs) or directory claims from external identity providers like RADIUS, LDAP, TACACS+, or Federated IDP. This could enable accounts to bypass crucial administrative role restrictions during the session establishment process, leading to potential security breaches.

Affected Version(s)

Fabric OS 0 < 10.0.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.