CVE-2026-87663: CWE-290: Authentication Bypass by Spoofing in Brocade Fabric OS
Description
An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. This flaw allows an attacker on a fabric-connected switch to escalate privileges and execute arbitrary root commands locally or on other managed fabric members where remote execution is enabled.
CVSS v4.0
Score 7.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-87663 is a vulnerability in Brocade Fabric OS's inter-switch remote execution service affecting versions prior to 9.2.2d and 10.0.0 through 10.0.0a1. The vulnerability arises because the receiving switch processes remote command execution IPC frames at an elevated privilege level without properly verifying transmitted parameters. This improper verification enables an attacker with access to a single fabric-connected switch to bypass authentication and perform command injection, leading to privilege escalation and arbitrary root command execution either locally or across other fabric members with remote execution enabled.
Potential Impact
An attacker with access to a fabric-connected switch can bypass authentication controls and execute arbitrary commands with root privileges on the local switch or other managed fabric members. This can lead to full compromise of the affected switches within the fabric, potentially disrupting network operations or allowing further malicious activity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to fabric-connected switches and disable remote execution functionality where possible to reduce exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c66x-7fmm-f2xw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-87663"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac747b92cdf04f656f93671
Added to database: 10/08/2026, 07:35:21 UTC
Last enriched: 10/08/2026, 07:49:04 UTC
Last updated: 10/09/2026, 05:48:07 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.