CVE-2026-87670: CWE-290: Authentication Bypass by Spoofing in Brocade Fabric OS
Description
CVE-2026-87670 is an authentication bypass vulnerability in Brocade Fabric OS REST API gateway versions before 10.0.1. The flaw arises because the authorization logic relies solely on client-controlled HTTP headers to protect restricted management endpoints. An authenticated user with any valid REST session can spoof these headers to access internal management endpoints unauthorizedly. This allows low-privilege users to view sensitive information such as chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
CVSS v4.0
Score 5.1medium
Affected software
Brocade
Fabric OS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Brocade Fabric OS versions prior to 10.0.1 affects the REST API gateway's authorization logic. The internal gate that restricts access to management endpoints depends exclusively on HTTP headers controlled by the client. Consequently, any authenticated user with a valid REST session can spoof these headers to bypass authorization controls and gain unauthorized access to sensitive internal management endpoints. The exposed information includes chassis metadata, hardware memory patrolling state, and firmware integrity audit logs. The CVSS 4.0 base score is 5.1, indicating a medium severity level. No known exploits are reported in the wild, and no vendor patch links are provided in the data.
Potential Impact
Low-privilege authenticated users can bypass authorization controls to access sensitive internal management endpoints. This exposure allows viewing of chassis metadata, hardware memory patrolling state, and firmware integrity audit logs, potentially aiding further reconnaissance or attacks. The vulnerability does not allow privilege escalation beyond the authenticated session or remote unauthenticated access according to the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix is referenced, users should monitor vendor communications for updates. Until a fix is available, restrict REST API access to trusted users and networks to minimize risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- brocade
- Date Reserved
- 2026-09-08T22:51:12.166Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac7081d2cdf04f656d93c76
Added to database: 10/08/2026, 03:03:57 UTC
Last enriched: 10/08/2026, 03:18:31 UTC
Last updated: 10/08/2026, 03:18:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.