CVE-2026-87660: High severity Brocade Fabric OS vulnerability
An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unprivileged local user can invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use Brocade Fabric OS versions before 9.2.2d, or versions 10.0.0 through 10.0.0a1.
What level of access does an attacker need?
An attacker needs local access as an unprivileged user. No user interaction is required.
What could an attacker do after exploitation?
An unprivileged local user could invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt storage fabric operations.