CVE-2026-94579: OS Command Injection
An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Affected deployments are Brocade Fabric OS versions before 9.2.2d and versions 10.0.0 through 10.0.0a1. Exploitation applies to SSH users authenticated through an external directory or AAA service.
What does an attacker need to exploit this issue?
The attacker needs valid authentication as a user whose externally supplied username or profile identifier contains shell metacharacters. The malicious value is triggered when the user's remote SSH session terminates.
What is the impact of successful exploitation?
Successful exploitation allows arbitrary command execution with root privileges on the affected device.