CVE-2026-87666
Received Received - Intake

OS Command Injection in Brocade Fabric OS

Vulnerability report for CVE-2026-87666, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When updating system timezone settings via the REST API or configuration download routines, the system fails to sanitize input values before processing them in underlying shell execution routines. An authenticated user with low-privilege administrative access can exploit this vulnerability by submitting a crafted timezone string containing shell metacharacters. Successful exploitation allows the attacker to escape the restricted management environment and execute arbitrary shell commands with elevated privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Brocade Fabric OS 0
Brocade Fabric OS 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an OS command injection vulnerability in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. It occurs in the time and zone management subsystem when updating timezone settings via REST API or configuration downloads. The system fails to sanitize input values before passing them to shell execution routines.

Detection Guidance

Detecting this vulnerability requires checking Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Verify system timezone settings via REST API or configuration files for crafted inputs. No specific commands are provided in the context.

Impact Analysis

An authenticated low-privilege user could exploit this to escape the management environment and execute arbitrary shell commands with elevated privileges. This could lead to full system compromise, data theft, or disruption of services.

Compliance Impact

This vulnerability allows an authenticated low-privilege user to execute arbitrary shell commands with elevated privileges by exploiting OS command injection in timezone settings. This could lead to unauthorized access, data exfiltration, or system manipulation, which may violate compliance requirements for GDPR (data protection) and HIPAA (healthcare data security) by enabling unauthorized access to sensitive information.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 9.2.2d or later, or 10.0.0a2 or later. Restrict low-privilege administrative access to prevent exploitation. Validate timezone input sanitization in REST API and configuration routines.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87666. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart