CVE-2026-87672
Received Received - Intake

Information Disclosure in Brocade Fabric OS SupportLink

Vulnerability report for CVE-2026-87672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An information disclosure vulnerability exists in the SupportLink diagnostic collection utilities of Brocade Fabric OS versions before 10.0.1. When SupportLink is configured to use an authenticated HTTP proxy, the system stores the full proxy URL. Anyone with access to the diagnostic support bundle, such as support personnel or users with access to file shares where support bundles are stored, can extract these cleartext proxy credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in Brocade Fabric OS versions before 10.0.1. When SupportLink uses an authenticated HTTP proxy, the full proxy URL including credentials is stored in cleartext. Attackers with access to diagnostic support bundles can extract these credentials.

Detection Guidance

Check SupportLink diagnostic support bundles for stored proxy URLs. Inspect configuration files in Brocade Fabric OS versions before 10.0.1 for cleartext proxy credentials. Look for URLs containing 'http://' or 'https://' in diagnostic logs or support bundle archives.

Impact Analysis

If you use Brocade Fabric OS versions before 10.0.1 with SupportLink configured to use an authenticated HTTP proxy, attackers could gain access to your proxy credentials. This could allow unauthorized network access or further exploitation of internal systems.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to sensitive data. Exposure of proxy credentials may violate data protection requirements for secure access controls and audit logging.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 10.0.1 or later to address the vulnerability. Remove any stored proxy credentials from diagnostic support bundles and configuration files. Restrict access to support bundles containing sensitive information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart