ZeroHour

CVE-2026-73711

niche

Unauthenticated privilege escalation in HPE Aruba Networking Fabric Composer API

CVSS 3.1
8.1 high
EPSS
<1%p21
Published
()
Modified
AI analysis

HPE (Aruba Networks) reports a privilege escalation flaw (CWE-269, improper privilege management) in the API endpoint of HPE Networking Fabric Composer, a data-center fabric orchestration product. An unauthenticated remote attacker can trigger it by sending crafted requests to the vulnerable API, though the high CVSS attack complexity (AC:H) indicates exploitation requires some difficult-to-meet conditions. Successful exploitation grants administrative privileges, which per HPE leads to complete compromise of the Fabric Composer host. Any organization running Fabric Composer to orchestrate Aruba CX-based network fabrics is potentially affected, particularly if the appliance's API is reachable beyond a restricted management network. There is currently no public proof-of-concept, no known exploitation, no CISA KEV listing, and EPSS is low (0.3% probability of exploitation in 30 days), so near-term risk is limited.

What to do: Track HPE's security advisory (CNA: [email protected]) and upgrade Fabric Composer to the patched release once published, since no fixed version is given in the current data. In the meantime, restrict access to the Fabric Composer API and management interface to trusted management networks and remove any direct internet exposure. Given the high attack complexity, absence of a public PoC, and low EPSS, immediate risk is limited, but internet-exposed or multi-tenant management deployments should be prioritized for patching.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer
Estimated exposure
nichelikely on the order of 1,000–10,000 deployments worldwide (estimate; no public install counts) — Fabric Composer is a specialized HPE data-center/private-cloud fabric orchestration platform deployed alongside Aruba CX switching rather than mass-market software, so its install base is plausibly in the low thousands of enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.