CVE-2026-73705
moderatePrivilege Escalation via Arbitrary File Write in HPE Aruba Networking Fabric Composer
HPE Aruba Networking Fabric Composer contains an arbitrary file write flaw (CWE-552) in its API that allows an authenticated low-privilege operator user to escalate privileges. An attacker triggers it via crafted API requests that write files to arbitrary locations, requiring only network access to the API, valid operator credentials, and no user interaction (per the CVSS vector AV:N/AC:L/PR:L/UI:N). Successful exploitation can result in arbitrary command execution on the underlying operating system, giving the attacker complete compromise of the Fabric Composer system, which orchestrates HPE Aruba data center switching fabrics. Organizations running Fabric Composer are affected, but the available data does not specify which versions are vulnerable or patched. There is no known public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%, 28th percentile), so no exploitation has been confirmed to date.
What to do: Check HPE's security advisory (issued via [email protected]) for patched Fabric Composer releases and upgrade, since fixed versions are not stated in this data. Until patched, restrict the Fabric Composer API to trusted management networks and minimize the number of operator-level accounts, because exploitation requires valid operator credentials. Monitor the appliance for unexpected privilege changes or unexplained operating-system commands.
| arubanetworks (HPE Aruba Networking) HPE Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-552
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.