{"success":true,"data":{"threats":[{"id":"3af01e6e-833e-419e-b18a-fe46fcc232b6","slug":"cve-2026-87687","externalId":"CVE-2026-87687","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87687 — An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1.","description":"An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access.","cveId":"CVE-2026-87687","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39081","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.0019,"epssPercentile":0.07917,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:17:56.360Z","addedAt":"2026-10-08T04:39:33.085Z","updatedAt":"2026-10-08T21:05:46.092Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87687","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87687","note":"authoritative record"}],"raw":{"id":"CVE-2026-87687","cveTags":[],"metrics":{"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-87687","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"version":"2.0.3","timestamp":"2026-10-08T12:47:53.665288Z"}}],"cvssMetricV40":[{"type":"Secondary","source":"sirt@brocade.com","cvssData":{"Safety":"NOT_DEFINED","version":"4.0","Recovery":"NOT_DEFINED","baseScore":8.5,"Automatable":"NOT_DEFINED","attackVector":"ADJACENT","baseSeverity":"HIGH","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","exploitMaturity":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","userInteraction":"NONE","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","subIntegrityImpact":"NONE","vulnIntegrityImpact":"HIGH","integrityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","subAvailabilityImpact":"NONE","vulnAvailabilityImpact":"NONE","availabilityRequirement":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","subConfidentialityImpact":"NONE","vulnConfidentialityImpact":"HIGH","confidentialityRequirement":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED"}}]},"affected":[{"source":"sirt@brocade.com","affectedData":[{"vendor":"Brocade","product":"Fabric OS","versions":[{"status":"affected","version":"0","lessThan":"9.2.2d","versionType":"Brocade FabricOS"},{"status":"affected","version":"10.0.0","versionType":"Brocade FabricOS","lessThanOrEqual":"10.0.0a1"}],"defaultStatus":"unaffected"}]}],"published":"2026-10-08T04:17:56.360","references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39081","source":"sirt@brocade.com"}],"vulnStatus":"Awaiting Analysis","weaknesses":[{"type":"Secondary","source":"sirt@brocade.com","description":[{"lang":"en","value":"CWE-88"}]}],"descriptions":[{"lang":"en","value":"An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This allows the user to perform unauthorized cross-fabric operations and view configuration details within tenants/Virtual Fabrics to which they have not been granted access."}],"lastModified":"2026-10-08T20:08:45.857","sourceIdentifier":"sirt@brocade.com"}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:28:06.396Z","durationMs":4,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2026-87687","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}