CVE-2026-87685: High severity Brocade Fabric OS vulnerability
An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments are Brocade Fabric OS systems running versions before 9.2.2d, or versions 10.0.0 through 10.0.0a1, where the WebTools management interface is used for configuration transfer requests.
What level of access does an attacker need?
Exploitation requires an authenticated administrative user. The attacker must submit a specially crafted status file path parameter in a configuration transfer request.
What can an attacker do after exploiting this issue?
The vulnerable process can be made to move an arbitrary system file into a predictable world-readable temporary directory. The stated impacts include persistent denial of service, destruction of critical system files, host compromise, and disclosure of sensitive data.
How can I assess whether exploitation may have occurred?
Review configuration transfer activity in the WebTools management interface for suspicious status file path values. Also investigate unexpected system-file moves, missing critical files, and sensitive files appearing in predictable world-readable temporary directories.