{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-94577","assignerOrgId":"87b297d7-335e-4844-9551-11b97995a791","state":"PUBLISHED","assignerShortName":"brocade","dateReserved":"2026-09-21T20:29:06.560Z","datePublished":"2026-10-08T04:18:30.464Z","dateUpdated":"2026-10-08T04:18:30.464Z"},"containers":{"cna":{"providerMetadata":{"orgId":"87b297d7-335e-4844-9551-11b97995a791","shortName":"brocade","dateUpdated":"2026-10-08T04:18:30.464Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-15","description":"CWE-15: External Control of System or Configuration Setting","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-180","descriptions":[{"lang":"en","value":"CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"}]}],"affected":[{"vendor":"Brocade","product":"Fabric OS","versions":[{"status":"affected","version":"0","lessThan":"9.2.2d","versionType":"Brocade FabricOS"},{"status":"affected","version":"10.0.0","lessThanOrEqual":"10.0.0a1","versionType":"Brocade FabricOS"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access Control (RBAC) validation checks. Successful exploitation allows an attacker to elevate privileges to root","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access Control (RBAC) validation checks. Successful exploitation allows an attacker to elevate privileges to root</p>"}]}],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39154"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7.3,"vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}}],"solutions":[{"lang":"en","value":"Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1","supportingMedia":[{"type":"text/html","base64":false,"value":"<div>Security update is provided in Brocade Fabric OS 9.2.2d and 10.0.1</div>"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}}}}