CVE-2026-73704
nicheCommand sanitization bypass in HPE Aruba Networking Fabric Composer API
HPE Aruba Networking Fabric Composer contains a command sanitization bypass (CWE-77) in its API, meaning specially crafted input from an authenticated user can evade neutralization and be processed as a command. An attacker who already holds a low-privilege operator account can send crafted requests through the API to escalate to administrative privileges, resulting in complete compromise of the affected system (CVSS 3.1: 8.8 high). Because authentication is required and there is no user interaction, only deployments where an attacker has obtained operator-level credentials are directly at risk. The affected product is HPE Aruba Networking Fabric Composer, with affected and fixed version ranges published by HPE (the assigned CNA) in its security advisory rather than in this data. Exploitation status: no in-the-wild reports, no public proof-of-concept, not in CISA KEV, and an EPSS 30-day exploitation probability of 0.3% (25th percentile) indicates modest near-term risk.
What to do: Upgrade Fabric Composer to a fixed release per HPE's security advisory for CVE-2026-73704, since no version numbers are provided in this data. Until patched, restrict access to the Fabric Composer API/management interface, limit operator accounts to trusted users, and review accounts and settings for unauthorized privilege changes. Because exploitation requires valid operator credentials, rotate or harden operator credentials if the appliance is reachable from less-trusted network segments.
| HPE (Aruba) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.