Race Condition and Thread-Safety Vulnerability in Brocade Fabric OS
CVE-2026-94584
2.1LOW
What is CVE-2026-94584?
A race condition and thread-safety issue exists in the web management daemon of Brocade Fabric OS. This vulnerability emerges during the handling of user authentication requests in a multi-threaded environment, resulting in PAM modules potentially processing outdated or incorrect client IP addresses and switch context numbers. Such discrepancies can compromise the integrity of audit records and may allow unauthorized access, particularly in scenarios relying on AAA evaluation or Calling-Station-ID ACL policies based on client IP attributes.
Affected Version(s)
Fabric OS 0 < 10.0.1