CVE-2026-94575: CWE-483: Incorrect Block Delimitation in Brocade Fabric OS
Description
A logic vulnerability exists in Brocade Fabric OS web management framework versions before 10.0.1. It allows an authenticated user with low privileges to bypass internal Role-Based Access Control (RBAC) checks under certain conditions. Exploiting this flaw lowers the authorization level of the active session, granting access to configuration settings normally restricted to administrators.
CVSS v4.0
Score 6.9medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94575 describes a logic vulnerability in Brocade Fabric OS web management framework versions prior to 10.0.1. This flaw permits an authenticated, low-privileged user to bypass inner RBAC checks under specific environmental conditions. Successful exploitation results in the active session's authorization mode being lowered, enabling access to restricted administrative configuration settings. The vulnerability is categorized under CWE-483 (Incorrect Block Delimitation). No known exploits are reported in the wild, and no official patch information is provided in the input data.
Potential Impact
An attacker with valid low-level credentials can escalate their access within the web management framework by bypassing RBAC controls. This leads to unauthorized access to sensitive configuration settings intended only for administrative roles, potentially compromising system integrity and management.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the web management interface to trusted users only and monitor for suspicious activity involving privilege escalation attempts.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-756g-ccf7-9xr2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-94575"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac747ba2cdf04f656f93680
Added to database: 10/08/2026, 07:35:22 UTC
Last enriched: 10/08/2026, 07:48:51 UTC
Last updated: 10/09/2026, 05:48:07 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.