ZeroHour

CVE-2026-73709

niche

OS Command Injection in HPE Aruba Networking Fabric Composer

CVSS 3.1
8.3 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-73709 is an operating system command injection flaw (CWE-78/CWE-77) in the underlying OS of HPE (Aruba Networks) Networking Fabric Composer. An unauthenticated attacker positioned on an adjacent network (e.g., the same management or fabric network segment) can trigger the flaw, but only if certain preconditions outside the attacker's control are met, which raises the attack complexity. If those preconditions are satisfied, the attacker can execute arbitrary commands on the underlying host operating system, giving them high-impact control over confidentiality, integrity, and availability on the appliance host. Only organizations running HPE Networking Fabric Composer, a fabric management platform for HPE Aruba networking environments, are exposed. There is no known exploitation: no public proof of concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%.

What to do: Review the HPE security advisory for CVE-2026-73709 to identify affected and fixed Fabric Composer releases, and upgrade as soon as a patched version is available. In the meantime, limit adjacent-network exposure of Fabric Composer appliances by isolating them to restricted management VLANs and restricting which devices can reach the appliance. Operators of Aruba fabric environments should check whether their deployment meets any preconditions HPE describes and monitor HPE communications for updates.

Affected
HPE (Aruba Networks) Networking Fabric Composer
Estimated exposure
nichelikely on the order of thousands of enterprise deployments worldwide (no public install count; niche management appliance) — Networking Fabric Composer is a niche data-center fabric management virtual appliance deployed once per enterprise switching fabric rather than at mass-market scale, so the install base is plausibly in the low thousands of sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.