Medium severityNVD Advisory· Published Oct 8, 2026
CVE-2026-94579
CVE-2026-94579
Description
An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or profile identifier contains shell metacharacters can trigger arbitrary command execution with root privileges when their remote SSH session closes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <9.2.2d, 10.0.0 through 10.0.0a1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.