CVE-2026-87667: High severity Brocade Fabric OS vulnerability
An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filters, the utility fails to sanitize user-supplied search string options before passing them to internal search commands. An authenticated user with low-privilege administrative access can exploit this vulnerability to read arbitrary files on the local operating system, including sensitive configuration files, system password hashes and system secrets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which Brocade Fabric OS releases are affected?
Affected releases are versions before 9.2.2d and versions 10.0.0 through 10.0.0a1. Version 9.2.2d is not included in the affected pre-9.2.2d range.
What access does an attacker need to exploit this issue?
The attacker must be authenticated and have low-privilege administrative access to the Fabric OS configuration management command-line utility. Exploitation occurs when using configuration-viewing commands with search pattern filters.
What information could be exposed if exploitation succeeds?
An attacker may read arbitrary local operating-system files, including sensitive configuration files, system password hashes, and system secrets.