CVE-2026-94585: High severity Brocade Fabric OS vulnerability
An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Which systems are affected?
The issue affects the web management interface of Brocade Fabric OS running on the MXG610 platform when the Fabric OS version is earlier than 9.2.2d.
What access does an attacker need to exploit this vulnerability?
An attacker does not need credentials or user interaction. They must be network-adjacent to the device and able to reach the web management interface.
What is the impact of successful exploitation?
Successful exploitation can give the attacker administrative access to the device management interface through an unauthenticated endpoint in the SSO workflow.
What version addresses the vulnerability?
Brocade Fabric OS 9.2.2d is not listed as affected; versions before 9.2.2d are affected.