OS Command Injection Vulnerability in Brocade Fabric OS by Broadcom
CVE-2026-94581
8.5HIGH
What is CVE-2026-94581?
An OS command injection vulnerability affects the REST API management interface of Brocade Fabric OS, allowing authenticated high-privileged remote attackers to execute arbitrary system commands with root permissions. By exploiting specially crafted parameter values with shell metacharacters, attackers with administrative rights can trigger command execution on the host system, posing a substantial threat to security.
Affected Version(s)
Fabric OS 0 < 9.2.2d
Fabric OS 10.0.0 <= 10.0.0a1