Back to database
Track12Low2.1VulnerabilityCVE-2026-94583No patch link observed

CVE-2026-94583 — A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1.

Published Oct 8, 2026, 03:16 AM UTCIngested 18h agoSource NVD(cve-db)CVE-2026-94583

Description

A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handling concurrent incoming network management FCIP requests, a timing window exists between when a request populates the address variable and when the service constructs and returns the response context. As a result, the first request adopts the modified context, causing the service to return sensitive management details or configuration data belonging to the second context back to the original requester.

CVSS v4.0 base metrics

CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2.1

Low severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Adjacent

Attack Vector

AC

High

Attack Complexity

AT

None

Attack Requirements

PR

Low

Privileges Required

UI

None

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)