CVE-2026-94575
Received
Received - Intake
Logic Bypass in Brocade Fabric OS Web Management
Vulnerability report for CVE-2026-94575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: Brocade Communications Systems, LLC
Description
Description
A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions. Successful exploitation lowers the system authorization mode for the active session context, allowing access to restricted configuration settings intended exclusively for administrative roles.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Brocade | Fabric | OS 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-483 | The code does not explicitly delimit a block that is intended to contain 2 or more statements, creating a logic error. |