An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in Brocade Fabric OS SSH Session Cleanup |
Thu, 08 Oct 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T04:35:58.198Z
Reserved: 2026-09-21T20:29:06.560Z
Link: CVE-2026-94579
No data.
Status : Received
Published: 2026-10-08T05:17:06.247
Modified: 2026-10-08T05:17:06.247
Link: CVE-2026-94579
No data.
OpenCVE Enrichment
Updated: 2026-10-08T06:30:17Z
Weaknesses