CVE-2026-87681: Brocade Fabric OS

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.

Affected products

  • Brocade Fabric OS: before 10.0.1 (fixed in 10.0.1)

Published 2026-10-08. Last modified 2026-10-08.