CVE-2026-73707
nicheAuthenticated privilege escalation in HPE Networking Fabric Composer API
HPE Networking Fabric Composer contains privilege escalation flaws (CWE-863, incorrect authorization) in its API, allowing an authenticated low-privilege operator user to perform state-changing actions that exceed their authorized level. An attacker needs valid operator-level credentials and network access to the product's API; no exploit chain or public proof-of-concept is known. On success, the attacker can modify the configuration of systems managed by Fabric Composer, such as the switching infrastructure under its control, with high integrity impact and some availability impact, though no confidentiality gain. Organizations running HPE (Aruba) Fabric Composer to orchestrate their Aruba networking fabric are affected. As of now there is no evidence of exploitation in the wild: the flaw is not in CISA KEV, has an EPSS 30-day probability of about 0.2% (9th percentile), and no public PoC exists.
What to do: Check the HPE Aruba security advisory for CVE-2026-73707 to identify whether your Fabric Composer release is affected, and upgrade to a fixed release per HPE's guidance. In the meantime, restrict access to the Fabric Composer API to trusted management networks, review whether operator-level accounts recently made configuration changes they should not have been able to perform, and minimize the number of active operator accounts and API tokens.
| HPE (Aruba Networks) HPE Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.