CVE-2026-94583: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Brocade Fabric OS
Description
CVE-2026-94583 is a race condition vulnerability in Brocade Fabric OS's REST management interface before version 10.0.1. It occurs when concurrent FCIP management requests cause improper synchronization in request processing, leading to leakage of sensitive management or configuration data from one request to another.
CVSS v4.0
Score 2.1low
Affected software
Brocade
Fabric OS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a race condition in the request processing logic of the REST management interface on Brocade Fabric OS versions prior to 10.0.1. When multiple FCIP network management requests are handled concurrently, a timing window exists between when a request sets an address variable and when the service constructs and returns the response context. Due to improper synchronization, the first request may receive sensitive management or configuration data intended for the second request, resulting in unintended data disclosure.
Potential Impact
The vulnerability can cause sensitive management details or configuration data to be leaked to an unauthorized requester due to the race condition in concurrent request handling. However, the CVSS score of 2.1 and vector indicate low severity with high attack complexity and limited impact scope.
Mitigation Recommendations
No official patch or vendor advisory is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid concurrent FCIP management requests or restrict access to the REST management interface to trusted administrators to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- brocade
- Date Reserved
- 2026-09-21T20:29:06.561Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac70ba22cdf04f656d9e1af
Added to database: 10/08/2026, 03:18:58 UTC
Last enriched: 10/08/2026, 03:33:15 UTC
Last updated: 10/08/2026, 03:33:52 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.