CVE-2026-87683
Received Received - Intake

Stack-Based Buffer Overflow in Brocade Fabric OS REST API

Vulnerability report for CVE-2026-87683, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow vulnerability in Brocade Fabric OS versions before 10.0.1. It occurs in the REST API management component when processing API requests. The system fails to validate array counts and string lengths in request payloads, allowing an authenticated attacker to send oversized parameters. This can corrupt memory on the execution stack, potentially causing a denial-of-service or arbitrary code execution within the management process.

Detection Guidance

Detecting this vulnerability requires monitoring the Brocade Fabric OS REST API service for crashes or unusual behavior when processing API requests. Check logs for daemon crashes or segmentation faults in the REST API service. Monitor network traffic for oversized payloads sent to the REST API endpoint. Ensure API request validation is enforced and test with crafted payloads in a controlled environment to observe crashes.

Impact Analysis

An attacker with REST API access could exploit this to crash the management daemon, disrupting device management operations. In severe cases, it may allow arbitrary code execution, enabling the attacker to gain control over the system or steal sensitive data. The impact depends on the attacker's access level and system configuration.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. A successful exploit may expose sensitive data, resulting in non-compliance with these regulations. Organizations must address this flaw to maintain compliance and protect data integrity.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 10.0.1 or later to address the stack-based buffer overflow vulnerabilities in the REST API management component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87683. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart