CVE-2026-94576: Medium severity Brocade Fabric OS vulnerability
An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can bypass authorization restrictions intended to prevent modifying another account's access privileges. Exploitation allows a lower-privileged user to assign administrative roles to a target account, leading to localized privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated lower-privileged user who can access the account management interface can exploit it under specific conditions. The issue enables that user to modify another account's access privileges and assign administrative roles.
Which Brocade Fabric OS versions are affected?
Affected versions are Brocade Fabric OS releases before 9.2.2d and versions from 10.0.0 through 10.0.0a1. The provided information does not identify other affected or fixed release ranges.
What is the impact of successful exploitation?
A lower-privileged authenticated user can assign administrative roles to a target account. This results in localized privilege escalation through the account management interface.