CVE-2026-94577: High severity Brocade Fabric OS vulnerability
A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access Control (RBAC) validation checks. Successful exploitation allows an attacker to elevate privileges to root
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must already be an authenticated user or have a local process, and must be able to manipulate the process execution environment. No user interaction is required.
Which Fabric OS versions should be remediated?
Affected releases are Brocade Fabric OS versions before 9.2.2d, and versions 10.0.0 through 10.0.0a1. Updating to 9.2.2d or later in that release line, or beyond 10.0.0a1 in the 10.0.0 line, addresses the affected version ranges described.