PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94578 Brocade CVE debrief

CVE-2026-94578 is a high-severity authorization logic vulnerability in Brocade Fabric OS versions before 10.0.1. This vulnerability allows remote authenticated users to gain root-equivalent chassis access controls by manipulating Vendor-Specific Attributes (VSAs) or directory claims from external identity providers. Brocade Fabric OS administrators and users with administrative roles should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access. The CVE record was published on 2026-10-08T02:28:03.936Z and has not been modified since then. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH.

Vendor
Brocade
Product
Fabric OS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Brocade Fabric OS administrators and users with administrative roles, as well as security teams and vulnerability management teams, should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access. The vulnerability affects Brocade Fabric OS versions before 10.0.1 and has a high CVSS severity score.

Why it matters

CVE-2026-94578 is a high-severity vulnerability in Brocade Fabric OS that allows remote authenticated users to gain root-equivalent chassis access controls. Administrators should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access.

  • Potential elevation of privileges for remote authenticated users
  • Possible unauthorized access to sensitive data and systems
  • Need for immediate patching or mitigation to prevent exploitation
  • Verification of system logs for suspicious activity

Technical summary

Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA integration framework. This vulnerability allows remote authenticated users to gain root-equivalent chassis access controls by returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH. Brocade Fabric OS administrators and users with administrative roles should prioritize patching or mitigation to prevent potential elevation of privileges and unauthorized access.

Defensive priority

High priority for Brocade Fabric OS administrators

Recommended defensive actions

  • Review and update Brocade Fabric OS to version 10.0.1 or later
  • Implement secure authentication and authorization mechanisms
  • Monitor system logs for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • technicalSummary

Evidence notes

The CVE record and source item provide details on an authorization logic vulnerability in Brocade Fabric OS versions before 10.0.1, allowing remote authenticated users to gain root-equivalent chassis access controls. The vulnerability is caused by the AAA integration framework's improper handling of Vendor-Specific Attributes (VSAs) or directory claims from external identity providers. Brocade Fabric OS administrators should verify the affected scope and severity, and plan vendor-supported updates or mitigations through normal change

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94578 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94578

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94578 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94578

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-94578

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94578.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://support.broadcom.com/external/content/SecurityAdvisories/0/39150

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.