CVE-2026-87685
Received Received - Intake

File Manipulation in Brocade Fabric OS

Vulnerability report for CVE-2026-87685, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Brocade Fabric OS 0
Brocade Fabric OS 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary file manipulation flaw in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. It occurs in the WebTools management interface when processing configuration transfer requests. The application fails to validate a user-supplied status file path parameter, allowing an authenticated admin to move arbitrary system files to a predictable, world-readable temporary directory.

Detection Guidance

This vulnerability can be detected by checking Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Verify the OS version using commands like 'version' or 'show version' in the WebTools management interface or CLI. Monitor for unauthorized file movements or unusual activity in temporary directories.

Impact Analysis

This vulnerability can lead to persistent Denial of Service (DoS), destruction of critical system files, host compromise, or sensitive data leakage. Attackers with admin access could manipulate files to disrupt operations or steal confidential information.

Compliance Impact

This vulnerability could lead to sensitive data leakage due to arbitrary file manipulation, which may expose confidential information. This violates GDPR's data protection principles and HIPAA's security requirements for safeguarding protected health information.

Mitigation Strategies

Immediately upgrade Brocade Fabric OS to version 9.2.2d or later, or 10.0.0a2 or later. Restrict administrative access to the WebTools interface. Review system logs for suspicious file manipulation activities. Apply network segmentation to limit exposure of the management interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87685. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart