ZeroHour

CVE-2026-73701

niche

Unauthenticated RCE in HPE Aruba Networking Fabric Composer underlying OS

CVSS 3.1
9.0 critical
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-73701 is an unauthenticated remote code execution flaw (code injection, CWE-94) in the underlying operating system of HPE Networking Fabric Composer, HPE Aruba's data-center network orchestration software. A remote attacker without credentials can attempt exploitation over the network, but success depends on certain preconditions outside the attacker's control, which is reflected in the high attack complexity of the 9.0 CVSS score. If those conditions are met, the attacker can execute arbitrary code as a privileged user on the host operating system, resulting in full compromise of the Fabric Composer host. Any organization running Fabric Composer deployments is potentially affected, though the product is a specialized on-premises management appliance rather than a mass-market endpoint. There is currently no known public proof-of-concept, no listing in CISA KEV, and a low 0.5% EPSS probability of exploitation in the next 30 days.

What to do: Monitor the HPE/Aruba security bulletin assigned by [email protected] for patched Fabric Composer releases and upgrade promptly once fixed versions are published; no fixed version numbers are provided in the current data. Until patched, restrict access to the Fabric Composer host to trusted management networks and avoid exposing it to the internet. Because exploitation requires preconditions outside the attacker's control and no public PoC exists, opportunistic exploitation risk is currently low, but re-check advisories and EPSS/KEV status as conditions evolve.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer (underlying operating system)
Estimated exposure
nichelikely on the order of thousands of on-prem management hosts worldwide, with only a small fraction internet-exposed — Fabric Composer is a specialized data-center orchestration appliance typically deployed one-per-site on management networks rather than at internet scale, so exposure is limited to enterprise data-center installs; no public install-count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.