ZeroHour

CVE-2026-73707

niche

Authenticated privilege escalation in HPE Networking Fabric Composer API

CVSS 3.1
8.5 high
EPSS
<1%p9
Published
()
Modified
AI analysis

HPE Networking Fabric Composer contains privilege escalation flaws (CWE-863, incorrect authorization) in its API, allowing an authenticated low-privilege operator user to perform state-changing actions that exceed their authorized level. An attacker needs valid operator-level credentials and network access to the product's API; no exploit chain or public proof-of-concept is known. On success, the attacker can modify the configuration of systems managed by Fabric Composer, such as the switching infrastructure under its control, with high integrity impact and some availability impact, though no confidentiality gain. Organizations running HPE (Aruba) Fabric Composer to orchestrate their Aruba networking fabric are affected. As of now there is no evidence of exploitation in the wild: the flaw is not in CISA KEV, has an EPSS 30-day probability of about 0.2% (9th percentile), and no public PoC exists.

What to do: Check the HPE Aruba security advisory for CVE-2026-73707 to identify whether your Fabric Composer release is affected, and upgrade to a fixed release per HPE's guidance. In the meantime, restrict access to the Fabric Composer API to trusted management networks, review whether operator-level accounts recently made configuration changes they should not have been able to perform, and minimize the number of active operator accounts and API tokens.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer
Estimated exposure
nichelikely on the order of thousands of enterprise installations worldwide, and only a small share internet-exposed (no public install-base count available) — Fabric Composer is an enterprise data-center fabric orchestration platform for Aruba/HPE switching, deployed per-site by organizations rather than at consumer or mass-SaaS scale, and its API is typically reachable only from management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.