CVE-2026-73701
nicheUnauthenticated RCE in HPE Aruba Networking Fabric Composer underlying OS
CVE-2026-73701 is an unauthenticated remote code execution flaw (code injection, CWE-94) in the underlying operating system of HPE Networking Fabric Composer, HPE Aruba's data-center network orchestration software. A remote attacker without credentials can attempt exploitation over the network, but success depends on certain preconditions outside the attacker's control, which is reflected in the high attack complexity of the 9.0 CVSS score. If those conditions are met, the attacker can execute arbitrary code as a privileged user on the host operating system, resulting in full compromise of the Fabric Composer host. Any organization running Fabric Composer deployments is potentially affected, though the product is a specialized on-premises management appliance rather than a mass-market endpoint. There is currently no known public proof-of-concept, no listing in CISA KEV, and a low 0.5% EPSS probability of exploitation in the next 30 days.
What to do: Monitor the HPE/Aruba security bulletin assigned by [email protected] for patched Fabric Composer releases and upgrade promptly once fixed versions are published; no fixed version numbers are provided in the current data. Until patched, restrict access to the Fabric Composer host to trusted management networks and avoid exposing it to the internet. Because exploitation requires preconditions outside the attacker's control and no public PoC exists, opportunistic exploitation risk is currently low, but re-check advisories and EPSS/KEV status as conditions evolve.
| HPE (Aruba Networks) HPE Networking Fabric Composer (underlying operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.