Stats Digest Feeds
← Back to all CVEs

CVE-2026-87664

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 08, 2026
Vendor unknown

Description

A session context forgery vulnerability exists in the web management daemon of Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. When processing local inter-process communication (IPC) storage callbacks, the service accepts and registers session structures including administrative role permissions, user identifiers, and authorization flagsβ€”without verifying the identity or authenticity of the sending process. An attacker can obtain elevated administrative privileges on the web management interface without legitimate authentication.

References