ZeroHour

CVE-2026-73705

moderate

Privilege Escalation via Arbitrary File Write in HPE Aruba Networking Fabric Composer

CVSS 3.1
8.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

HPE Aruba Networking Fabric Composer contains an arbitrary file write flaw (CWE-552) in its API that allows an authenticated low-privilege operator user to escalate privileges. An attacker triggers it via crafted API requests that write files to arbitrary locations, requiring only network access to the API, valid operator credentials, and no user interaction (per the CVSS vector AV:N/AC:L/PR:L/UI:N). Successful exploitation can result in arbitrary command execution on the underlying operating system, giving the attacker complete compromise of the Fabric Composer system, which orchestrates HPE Aruba data center switching fabrics. Organizations running Fabric Composer are affected, but the available data does not specify which versions are vulnerable or patched. There is no known public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%, 28th percentile), so no exploitation has been confirmed to date.

What to do: Check HPE's security advisory (issued via [email protected]) for patched Fabric Composer releases and upgrade, since fixed versions are not stated in this data. Until patched, restrict the Fabric Composer API to trusted management networks and minimize the number of operator-level accounts, because exploitation requires valid operator credentials. Monitor the appliance for unexpected privilege changes or unexplained operating-system commands.

Affected
arubanetworks (HPE Aruba Networking) HPE Networking Fabric Composer
Estimated exposure
moderatelikely low thousands of virtual-appliance deployments worldwide — Fabric Composer is a specialized data center fabric-management virtual appliance deployed alongside HPE Aruba data center switching rather than a mass-market product, and no public install counts or internet-exposure scan figures exist, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-552
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.