CVE-2026-87679
Received Received - Intake

Heap Corruption in Brocade Fabric OS via Trunk Configuration

Vulnerability report for CVE-2026-87679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable number of elements. An authenticated administrator can exploit this vulnerability via crafted REST API requests containing an excessive number of list delimiters, causing heap corruption that can result in service crash or arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap corruption vulnerability in Brocade Fabric OS versions before 10.0.1. When processing trunk configuration operations, the system parses user-supplied list strings into heap arrays without checking the maximum number of elements. An authenticated admin can send crafted REST API requests with excessive list delimiters to trigger heap corruption, potentially causing service crashes or arbitrary code execution.

Detection Guidance

This vulnerability requires authenticated access to Brocade Fabric OS systems running versions before 10.0.1. Detection involves monitoring for heap corruption or service crashes during trunk configuration operations. Check system logs for REST API requests with excessive list delimiters or malformed payloads. No specific commands are provided in the available context.

Impact Analysis

If exploited, this vulnerability could allow an authenticated administrator to crash the Brocade Fabric OS service or execute arbitrary code on the affected system. This may lead to unauthorized access, data breaches, or disruption of network services relying on the Fabric OS.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized code execution or service disruption on affected Brocade Fabric OS systems. Exploitation may lead to data breaches or unauthorized access, which are key concerns under these regulations.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 10.0.1 or later to address the heap corruption vulnerability in trunk configuration operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart