CVE-2026-87663: Command Injection
An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which systems are exposed to exploitation?
Brocade Fabric OS versions before 9.2.2d and versions 10.0.0 through 10.0.0a1 are affected. Remote execution functionality must be enabled on the managed fabric members targeted by the attacker.
What access does an attacker need?
The attacker needs control of, or access to, a switch connected to the same fabric. Exploitation does not require user interaction.
What is the potential impact after exploitation?
An attacker can bypass authentication and escalate privileges to execute arbitrary commands as root. Commands may be executed on the attacker-controlled switch locally or against other managed members of the fabric.