Back to database
Schedule38Medium6.9VulnerabilityCVE-2026-87668No patch link observed

CVE-2026-87668 — A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1.

Published Oct 8, 2026, 03:16 AM UTCIngested 18h agoSource NVD(cve-db)CVE-2026-87668

Description

A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash).

CVSS v4.0 base metrics

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.9

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Adjacent

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

High

Privileges Required

UI

None

User Interaction

VC

None

Confidentiality (Vulnerable System)

VI

Low

Integrity (Vulnerable System)

VA

High

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)