CVE-2026-73708
nicheAuthenticated Privilege Escalation in HPE Aruba Networking Fabric Composer API
CVE-2026-73708 is a business logic flaw (CWE-863, incorrect authorization) in the API of HPE Aruba Networking Fabric Composer. It is triggered when an authenticated low-privilege operator issues API requests that bypass the platform's authorization checks, allowing actions beyond the operator's assigned privilege level. A successful attacker gains elevated privileges on the vulnerable system and can modify settings they should not be able to change, with high impact on confidentiality and integrity and low impact on availability per the CVSS score of 8.3. Only organizations running HPE Aruba Networking Fabric Composer, HPE's orchestration platform for data center networking fabrics, are affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Upgrade Fabric Composer to the fixed release identified in HPE's security advisory for CVE-2026-73708, since exact version numbers are not available in this data. Until patched, restrict API access to trusted management networks and review which accounts hold the operator role. Audit recent settings changes made by operator-level accounts to detect any prior privilege abuse.
| HPE (Aruba Networks) Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.