An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary File Deletion via REST API in Brocade Fabric OS | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T03:11:54.902Z
Reserved: 2026-09-21T20:29:06.560Z
Link: CVE-2026-94580
No data.
Status : Received
Published: 2026-10-08T04:18:00.347
Modified: 2026-10-08T04:18:00.347
Link: CVE-2026-94580
No data.
OpenCVE Enrichment
Updated: 2026-10-08T04:30:13Z
Weaknesses