Description
An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Security update is provided in Brocade Fabric OS 10.0.1
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T00:57:36.385Z
Reserved: 2026-09-08T22:51:12.186Z
Link: CVE-2026-87681
No data.
Status : Received
Published: 2026-10-08T01:16:32.620
Modified: 2026-10-08T01:16:32.620
Link: CVE-2026-87681
No data.
OpenCVE Enrichment
No data.
Weaknesses