CVE-2026-87670: Medium severity Brocade Fabric OS vulnerability
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OS REST API gatewayto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Brocade Fabric OS versions before 10.0.1 are affected where the REST API gateway is available. The issue concerns restricted internal management endpoints behind that gateway.
What does an attacker need to exploit this issue?
An attacker needs an authenticated REST session, but any valid REST user account is sufficient. They can spoof client-controlled HTTP headers that the authorization gate trusts.
What access can a successful attacker obtain?
A low-privilege authenticated user can access internal management endpoints and view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
How can exposure be reduced before upgrading?
The provided information identifies spoofable HTTP headers as the bypass mechanism, but does not specify a supported workaround. Restricting REST API access to trusted authenticated administrators would reduce the population able to exploit it.