Medium severityNVD Advisory· Published Oct 8, 2026
CVE-2026-87670
CVE-2026-87670
Description
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Brocade Fabric OS: 19 Vulnerabilities Including High-Severity Flaws Disclosed TogetherVypr Intelligence · Oct 8, 2026