CVE-2026-87680
Received Received - Intake

Command Injection in Brocade Fabric OS

Vulnerability report for CVE-2026-87680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

A command injection vulnerability in the REST API management interface of Brocade Fabric OS versions before 10.0.1 allows an authenticated user to execute arbitrary system commands via crafted input parameters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in the REST API management interface of Brocade Fabric OS versions before 10.0.1. An authenticated user can exploit crafted input parameters to execute arbitrary system commands on the affected system.

Detection Guidance

Detecting this vulnerability requires checking for Brocade Fabric OS versions before 10.0.1. Use commands like 'show version' or 'version' on the Brocade device to verify the installed OS version. Inspect REST API logs for unusual input parameters or command execution patterns.

Impact Analysis

An attacker with access could execute unauthorized commands, potentially leading to system compromise, data theft, or disruption of services. This requires authentication but could allow lateral movement within a network if credentials are obtained.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance penalties if exploited due to inadequate security controls.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 10.0.1 or later. Restrict access to the REST API management interface to trusted users only. Monitor network traffic for suspicious activity targeting the REST API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart