CVE-2026-87670EPSS p2.9%
CVE-2026-87670CVE-2026-87670
Description
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.
Scoring
| EPSS | 0.14% probability of exploitation · percentile 2.9% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |