CVE-2026-87663
Received Received - Intake

Authentication Bypass and Command Injection in Brocade Fabric OS

Vulnerability report for CVE-2026-87663, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Brocade Fabric OS 0
Brocade Fabric OS 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass and command injection flaw in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. It allows an attacker on a connected switch to execute arbitrary root commands locally or across other fabric members by exploiting improper parameter verification in remote command execution IPC frames.

Detection Guidance

This vulnerability cannot be directly detected using standard commands as it involves an authentication bypass and command injection in Brocade Fabric OS inter-switch communication. Check for unauthorized remote command execution attempts in switch logs or fabric traffic. Verify Fabric OS versions are updated to 9.2.2d or later and 10.0.0a2 or later to confirm patch status.

Impact Analysis

An attacker could gain elevated privileges, execute malicious commands, and potentially take control of the affected switches or the entire fabric. This could lead to unauthorized access, data breaches, or disruption of network services.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 9.2.2d or later, or 10.0.0a2 or later if using version 10.0.0. Disable remote execution functionality if not required. Restrict access to fabric-connected switches to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87663. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart