Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-87681

Quick assessment

Affected
Brocade Fabric OS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Brocade Fabric OS 10.0.1 之前的版本中,其基于角色的访问控制(RBAC)验证引擎存在访问控制绕过漏洞。在处理某些管理协议操作时,RBAC 引擎在权限检查过程中错误地对非标准操作码进行分类,从而导致具有只读管理权限的已认证用户能够绕过访问控制限制,执行受限的管理操作。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87681

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Brocade Fabric OS 0 ~ 10.0.1 -

II. Public POCs for CVE-2026-87681

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87681

请登录查看更多情报信息。

Other References for CVE-2026-87681 (1)

Same Patch Batch · Brocade · 2026-10-08 · 19 CVEs total

CVE-2026-87684 8.7 HIGH Brocade Fabric<10.0.1 SNMP守护进程栈缓冲区溢出漏洞
CVE-2026-87682 8.6 HIGH Brocade Fabric OS<10.0.1命令注入漏洞
CVE-2026-87683 8.6 HIGH Brocade Fabric OS堆缓冲区溢出漏洞
CVE-2026-87679 8.5 HIGH Brocade Fabric OS<10.0.1堆溢出漏洞
CVE-2026-87680 8.5 HIGH Brocade Fabric OS命令注入漏洞
CVE-2026-94578 7.5 HIGH Brocade Fabric OS授权逻辑漏洞
CVE-2026-87671 7.1 HIGH Brocade Fabric OS越界读取致DoS漏洞
CVE-2026-87659 7.1 HIGH Brocade Fabric OS<10.0.1认证绕过漏洞
CVE-2026-87668 6.9 MEDIUM Brocade Fabric OS堆栈溢出致拒绝服务漏洞
CVE-2026-87678 6.9 MEDIUM Brocade Fabric OS<10.0.1注入漏洞
CVE-2026-87676 6.9 MEDIUM Brocade Fabric OS堆溢出致DoS
CVE-2026-94582 6.8 MEDIUM Brocade Fabric OS 10.0.1前版本FSPF内存溢出漏洞
CVE-2026-87672 6.8 MEDIUM Brocade Fabric OS 信息泄露漏洞
CVE-2026-87665 6.0 MEDIUM Brocade Fabric OS IKEv2栈溢出漏洞
CVE-2026-87686 5.3 MEDIUM Brocade Fabric OS 认证绕过与访问控制漏洞
CVE-2026-87669 5.1 MEDIUM Brocade Fabric OS <10.0.1 REST API越权漏洞
CVE-2026-87670 5.1 MEDIUM Brocade Fabric OS授权逻辑漏洞
CVE-2026-94583 2.1 LOW Brocade Fabric OS竞态条件漏洞致敏感信息泄露

IV. Related Vulnerabilities

V. Comments for CVE-2026-87681

No comments yet


Leave a comment