CVE-2026-87664
Received Received - Intake

Session Context Forgery in Brocade Fabric OS Web Management

Vulnerability report for CVE-2026-87664, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

A session context forgery vulnerability exists in the web management daemon of Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. When processing local inter-process communication (IPC) storage callbacks, the service accepts and registers session structures including administrative role permissions, user identifiers, and authorization flagsβ€”without verifying the identity or authenticity of the sending process. An attacker can obtain elevated administrative privileges on the web management interface without legitimate authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Brocade Fabric OS 0
Brocade Fabric OS 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a session context forgery issue in Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. It allows an attacker to gain elevated administrative privileges on the web management interface without proper authentication by exploiting a flaw in how session structures are processed during local inter-process communication.

Detection Guidance

This vulnerability involves session context forgery in Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. Detection requires checking for unauthorized administrative access or unusual session activity in the web management interface. Review logs for unexpected privilege escalations or IPC callbacks without proper authentication. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to take control of the web management interface, perform unauthorized actions, or access sensitive data. This could lead to system compromise, data breaches, or disruption of services if administrative privileges are misused.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if such breaches occur due to unpatched systems.

Mitigation Strategies

Apply the latest security patches from Brocade for Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1 to fix the session context forgery vulnerability. Disable unnecessary web management interfaces if possible and restrict access to administrative roles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87664. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart