An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T00:57:36.385Z
Reserved: 2026-09-08T22:51:12.186Z
Link: CVE-2026-87681
No data.
Status : Received
Published: 2026-10-08T01:16:32.620
Modified: 2026-10-08T01:16:32.620
Link: CVE-2026-87681
No data.
OpenCVE Enrichment
No data.
Weaknesses