CVE-2026-87675
An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download.
| CWE | CWE-78 |
| Vendor | brocade |
| Product | fabric os |
| Published | Oct 8, 2026 |
Get instant alerts for brocade fabric os
Be the first to know when new unknown vulnerabilities affecting brocade fabric os are published โ delivered to Slack, Telegram or Discord.