PatchSiren cyber security CVE debrief
CVE-2026-94578 Brocade CVE debrief
CVE-2026-94578 is a high-severity authorization logic vulnerability in Brocade Fabric OS versions before 10.0.1. This vulnerability allows remote authenticated users to gain root-equivalent chassis access controls by manipulating Vendor-Specific Attributes (VSAs) or directory claims from external identity providers. Brocade Fabric OS administrators and users with administrative roles should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access. The CVE record was published on 2026-10-08T02:28:03.936Z and has not been modified since then. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH.
- Vendor
- Brocade
- Product
- Fabric OS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Brocade Fabric OS administrators and users with administrative roles, as well as security teams and vulnerability management teams, should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access. The vulnerability affects Brocade Fabric OS versions before 10.0.1 and has a high CVSS severity score.
Why it matters
CVE-2026-94578 is a high-severity vulnerability in Brocade Fabric OS that allows remote authenticated users to gain root-equivalent chassis access controls. Administrators should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access.
- Potential elevation of privileges for remote authenticated users
- Possible unauthorized access to sensitive data and systems
- Need for immediate patching or mitigation to prevent exploitation
- Verification of system logs for suspicious activity
Technical summary
Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA integration framework. This vulnerability allows remote authenticated users to gain root-equivalent chassis access controls by returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH. Brocade Fabric OS administrators and users with administrative roles should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access.
Defensive priority
High priority for Brocade Fabric OS administrators
Recommended defensive actions
- Review and update Brocade Fabric OS to version 10.0.1 or later
- Implement secure authentication and authorization mechanisms
- Monitor system logs for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- technicalSummary
Evidence notes
The CVE record and source item provide details on an authorization logic vulnerability in Brocade Fabric OS versions before 10.0.1, allowing remote authenticated users to gain root-equivalent chassis access controls. The vulnerability is caused by the AAA integration framework's improper handling of Vendor-Specific Attributes (VSAs) or directory claims from external identity providers. Brocade Fabric OS administrators should verify the affected scope and severity, and plan vendor-supported updates or mitigations through normal change
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94578 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94578
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94578 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94578
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-94578
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94578.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/39150
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.