ZeroHour

CVE-2026-73704

niche

Command sanitization bypass in HPE Aruba Networking Fabric Composer API

CVSS 3.1
8.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

HPE Aruba Networking Fabric Composer contains a command sanitization bypass (CWE-77) in its API, meaning specially crafted input from an authenticated user can evade neutralization and be processed as a command. An attacker who already holds a low-privilege operator account can send crafted requests through the API to escalate to administrative privileges, resulting in complete compromise of the affected system (CVSS 3.1: 8.8 high). Because authentication is required and there is no user interaction, only deployments where an attacker has obtained operator-level credentials are directly at risk. The affected product is HPE Aruba Networking Fabric Composer, with affected and fixed version ranges published by HPE (the assigned CNA) in its security advisory rather than in this data. Exploitation status: no in-the-wild reports, no public proof-of-concept, not in CISA KEV, and an EPSS 30-day exploitation probability of 0.3% (25th percentile) indicates modest near-term risk.

What to do: Upgrade Fabric Composer to a fixed release per HPE's security advisory for CVE-2026-73704, since no version numbers are provided in this data. Until patched, restrict access to the Fabric Composer API/management interface, limit operator accounts to trusted users, and review accounts and settings for unauthorized privilege changes. Because exploitation requires valid operator credentials, rotate or harden operator credentials if the appliance is reachable from less-trusted network segments.

Affected
HPE (Aruba) HPE Aruba Networking Fabric Composer
Estimated exposure
nichelikely hundreds to low thousands of appliance deployments — Fabric Composer is a management/orchestration platform for HPE Aruba data-center switching, typically deployed as one appliance instance per enterprise data-center fabric rather than at internet or consumer scale, and no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.