OS Command Injection in Brocade Fabric OS Affecting SSH Session Management
CVE-2026-94579

5.4MEDIUM

Key Information:

Vendor

Brocade

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-94579?

An OS command injection vulnerability is present in the PAM session cleanup routines during the termination of SSH sessions on affected Brocade Fabric OS versions. This flaw allows an authenticated user, when their username or profile identifier includes shell metacharacters, to execute arbitrary commands with root privileges as their SSH session terminates. This vulnerability can be triggered through authenticated access via an external directory or AAA service, potentially compromising system integrity.

Affected Version(s)

Fabric OS 0 < 9.2.2d

Fabric OS 10.0.0 <= 10.0.0a1

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.