CVE-2026-94586: OS Command Injection
A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can supply malicious parameter strings to execute arbitrary shell commands on the switch with root privileges
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 9.2.2d - Upgrade
Upgrade
Brocade Fabric OSto a version that resolves this vulnerability.Fixed in 10.0.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user must have permissions to perform configuration downloads using remote server profiles in the WebTools administrative interface. The attack does not require user interaction or additional attack conditions.
Which Fabric OS versions are affected?
The affected versions are Brocade Fabric OS releases before 9.2.2d, and versions 10.0.0 through 10.0.0a1.
What level of access could exploitation provide?
An attacker can supply malicious parameter strings during configuration download or file transfer operations to execute arbitrary shell commands on the switch with root privileges.