Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Brocade Fabric OS Command Injection via WebTools Configuration Operations |
Thu, 08 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can supply malicious parameter strings to execute arbitrary shell commands on the switch with root privileges | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T17:56:11.829Z
Reserved: 2026-09-21T20:30:21.087Z
Link: CVE-2026-94586
No data.
Status : Received
Published: 2026-10-08T05:17:06.660
Modified: 2026-10-08T18:18:32.950
Link: CVE-2026-94586
No data.
OpenCVE Enrichment
Updated: 2026-10-08T06:00:10Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')