CVE-2026-94576: Brocade Fabric OS

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can bypass authorization restrictions intended to prevent modifying another account's access privileges. Exploitation allows a lower-privileged user to assign administrative roles to a target account, leading to localized privilege escalation.

Affected products

  • Brocade Fabric OS: before 9.2.2d (fixed in 9.2.2d); from 10.0.0, up to and including 10.0.0a1

Published 2026-10-08. Last modified 2026-10-08.