CVE-2026-87661: CRLF Injection
Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 directly accepts Apache configuration file data during service setup or re-initialization. An attacker capable of corrupting the configuration structure will prevent the web management service from starting or recovering during service bring-up, leading to a persistent Denial of Service (DoS) of the administrative web interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which systems are affected?
Brocade Fabric OS versions before 9.2.2d, and versions 10.0.0 through 10.0.0a1, are affected.
What access does an attacker need to exploit this issue?
The attacker must be capable of corrupting the configuration structure. The provided CVSS vector indicates high privileges are required and exploitation is network-accessible without user interaction.
What is the operational impact?
A successful attack can prevent the administrative web management service from starting or recovering during service setup or re-initialization. This causes a persistent denial of service affecting the administrative web interface.