ZeroHour

CVE-2026-73702

niche

Authenticated Privilege Escalation in HPE Networking Fabric Composer API

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

HPE Networking Fabric Composer contains an incorrect-authorization flaw (CWE-863) in its API that allows an authenticated user holding only operator-level privileges to escalate to full administrative permissions. An attacker triggers it by sending API requests with valid low-privilege operator credentials, since the API fails to correctly enforce role-based authorization; the CVSS vector confirms it is network-exploitable with low complexity and no user interaction, but requires existing low-privilege access. Successful exploitation grants administrative control of the Fabric Composer instance, which HPE assesses as leading to complete system compromise of the orchestration platform (and, by extension, the network fabric it manages). Any organization running HPE/Aruba Networking Fabric Composer to orchestrate its data-center switching fabric is potentially affected. There is no public proof-of-concept, it is not listed in CISA KEV, and EPSS is low (0.3%, 21st percentile), so no exploitation is currently known.

What to do: Check the HPE (Aruba) support portal for the security advisory covering CVE-2026-73702 and upgrade Fabric Composer to the fixed release it specifies. Until patched, restrict network access to the Fabric Composer API and management interface to trusted management segments and audit operator accounts for unexpected privilege changes or administrative activity. If compromise is suspected, rotate credentials for all Fabric Composer accounts.

Affected
hpe (arubanetworks) HPE Networking Fabric Composer
Estimated exposure
nichelikely on the order of thousands of deployments worldwide (specialized enterprise data-center orchestrator), not precisely known — Fabric Composer is a niche HPE/Aruba virtual-appliance orchestrator deployed per enterprise data-center network fabric rather than a mass-market product, and with no public install-base counts this order-of-magnitude estimate is based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.