CVE-2026-87677: OS Command Injection
An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When an administrator initiates an account deletion, the system invokes an internal maintenance routine to clean up cryptographic keys associated with the target account. Malformed account names previously accepted by Fabric OS can cause the execution of embedded shell metacharacters, triggering command injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which Fabric OS releases should be prioritized for remediation?
Affected releases are Brocade Fabric OS versions before 9.2.2d and versions 10.0.0 through 10.0.0a1.
What conditions are required for exploitation?
A malformed account name that was previously accepted by Fabric OS must be deleted. The command injection is triggered when an administrator initiates deletion of that account, causing the internal cryptographic-key cleanup routine to run.