Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Security update is provided in Brocade Fabric OS 10.0.1
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary File Deletion via REST API in Brocade Fabric OS | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T15:43:20.681Z
Reserved: 2026-09-21T20:29:06.560Z
Link: CVE-2026-94580
No data.
Status : Received
Published: 2026-10-08T04:18:00.347
Modified: 2026-10-08T16:18:00.970
Link: CVE-2026-94580
No data.
OpenCVE Enrichment
Updated: 2026-10-08T04:30:13Z