An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When an administrator initiates an account deletion, the system invokes an internal maintenance routine to clean up cryptographic keys associated with the target account. Malformed account names previously accepted by Fabric OS can cause the execution of embedded shell metacharacters, triggering command injection.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in Fabric OS Account Management | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When an administrator initiates an account deletion, the system invokes an internal maintenance routine to clean up cryptographic keys associated with the target account. Malformed account names previously accepted by Fabric OS can cause the execution of embedded shell metacharacters, triggering command injection. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T04:25:22.469Z
Reserved: 2026-09-08T22:51:12.167Z
Link: CVE-2026-87677
No data.
Status : Received
Published: 2026-10-08T05:17:05.833
Modified: 2026-10-08T05:17:05.833
Link: CVE-2026-87677
No data.
OpenCVE Enrichment
Updated: 2026-10-08T05:30:17Z
Weaknesses