Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.

Project Subscriptions

Vendors Products
Brocade Subscribe
Fabric Os Subscribe
Advisories

No advisories yet.

Fixes

Solution

Security update is provided in Brocade Fabric OS 10.0.1


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Privilege Escalation via AAA Integration in Brocade Fabric OS

Thu, 08 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Brocade
Brocade fabric Os
Vendors & Products Brocade
Brocade fabric Os

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2026-10-08T17:20:36.425Z

Reserved: 2026-09-21T20:29:06.560Z

Link: CVE-2026-94578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.840

Modified: 2026-10-08T03:16:37.840

Link: CVE-2026-94578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:00:11Z

Weaknesses