ZeroHour

CVE-2026-73708

niche

Authenticated Privilege Escalation in HPE Aruba Networking Fabric Composer API

CVSS 3.1
8.3 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-73708 is a business logic flaw (CWE-863, incorrect authorization) in the API of HPE Aruba Networking Fabric Composer. It is triggered when an authenticated low-privilege operator issues API requests that bypass the platform's authorization checks, allowing actions beyond the operator's assigned privilege level. A successful attacker gains elevated privileges on the vulnerable system and can modify settings they should not be able to change, with high impact on confidentiality and integrity and low impact on availability per the CVSS score of 8.3. Only organizations running HPE Aruba Networking Fabric Composer, HPE's orchestration platform for data center networking fabrics, are affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Upgrade Fabric Composer to the fixed release identified in HPE's security advisory for CVE-2026-73708, since exact version numbers are not available in this data. Until patched, restrict API access to trusted management networks and review which accounts hold the operator role. Audit recent settings changes made by operator-level accounts to detect any prior privilege abuse.

Affected
HPE (Aruba Networks) Aruba Networking Fabric Composer
Estimated exposure
nichelikely hundreds to a few thousand deployments (typically one management appliance per data center fabric) — Fabric Composer is a specialized enterprise product used to orchestrate HPE Aruba data center switching, generally deployed as a single management node per site rather than at scale like consumer or SMB products, so the installed base is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.