Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Shell Command Execution via Unsanitized Parameters in Brocade Fabric OS Upgrade Process | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell metacharacters in fields like the host or file path are not stripped or sanitized, an attacker can execute arbitrary shell commands with the firmware management daemon's elevated privileges. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T04:02:32.204Z
Reserved: 2026-09-08T22:51:12.105Z
Link: CVE-2026-87662
No data.
Status : Received
Published: 2026-10-08T05:17:05.433
Modified: 2026-10-08T05:17:05.433
Link: CVE-2026-87662
No data.
OpenCVE Enrichment
Updated: 2026-10-08T05:30:17Z