CVE-2026-87664: High severity Brocade Fabric OS vulnerability
A session context forgery vulnerability exists in the web management daemon of Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. When processing local inter-process communication (IPC) storage callbacks, the service accepts and registers session structures including administrative role permissions, user identifiers, and authorization flags—without verifying the identity or authenticity of the sending process. An attacker can obtain elevated administrative privileges on the web management interface without legitimate authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs local access with low privileges and does not require user interaction. Exploitation involves sending forged session structures through local IPC storage callbacks.
What systems should be checked for exposure?
Check Brocade Fabric OS systems running version 9.2.2d or versions 10.0.0 through 10.0.0a1. The affected component is the web management daemon.
What could an attacker gain after successful exploitation?
An attacker can register a forged session containing administrative roles, user identifiers, and authorization flags, resulting in elevated administrative privileges on the web management interface. The CVSS vector indicates high impacts to confidentiality, integrity, and availability.