CVE-2026-87670
Received Received - Intake

Authorization Bypass in Brocade Fabric OS REST API

Vulnerability report for CVE-2026-87670, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authorization logic vulnerability in Brocade Fabric OS versions before 10.0.1. The REST API gateway uses client-controlled HTTP headers to guard restricted management endpoints. An authenticated user can manipulate these headers to bypass access controls and gain unauthorized access to internal management functions.

Detection Guidance

Detecting this vulnerability requires checking Brocade Fabric OS versions before 10.0.1 and inspecting REST API header handling. Verify OS version with 'version' command. Monitor HTTP headers in REST API logs for unexpected client-controlled values. Check for unauthorized access attempts to internal management endpoints.

Impact Analysis

A low-privilege user could exploit this to view sensitive system information such as chassis metadata, hardware memory states, and firmware audit logs. This could lead to information disclosure and potential further exploitation of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive system metadata and audit logs, which may include personal or confidential data. Such exposure risks violating GDPR (data protection) and HIPAA (health information privacy) by allowing low-privilege users to view restricted information without proper authorization.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 10.0.1 or later to address the authorization logic flaw in the REST API gateway.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87670. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart