CVE-2026-0383 PUBLISHED

Information disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0

Assigner: brocade
Reserved: 05.11.2025 Published: 03.02.2026 Updated: 03.02.2026

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor Brocade
Product Fabric OS
Versions Default: unaffected
  • Version before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0 is affected

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-43: Exploiting Multiple Input Interpretation Layers