CVE-2026-94578
Received Received - Intake

Authorization Bypass in Brocade Fabric OS AAA Framework

Vulnerability report for CVE-2026-94578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Brocade Communications Systems, LLC

Description

Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Brocade Fabric OS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Brocade Fabric OS versions before 10.0.1 allows remote authenticated users to gain root-equivalent chassis access controls by exploiting an authorization logic flaw in the AAA integration framework. Attackers can bypass administrative role restrictions by sending crafted Vendor-Specific Attributes or directory claims from external identity providers like RADIUS, LDAP, TACACS+, or Federated IDP during session setup.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to gain full administrative control over Brocade Fabric OS devices, potentially leading to data breaches, system compromise, or disruption of network operations. Organizations using affected versions may face unauthorized access to sensitive network infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR, HIPAA, and other regulations. Organizations may face legal penalties, data breach notifications, and reputational damage due to compromised administrative controls.

Mitigation Strategies

Upgrade Brocade Fabric OS to version 10.0.1 or later to address the authorization logic vulnerability in the AAA integration framework.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart