CVE-2026-73711
nicheUnauthenticated privilege escalation in HPE Aruba Networking Fabric Composer API
HPE (Aruba Networks) reports a privilege escalation flaw (CWE-269, improper privilege management) in the API endpoint of HPE Networking Fabric Composer, a data-center fabric orchestration product. An unauthenticated remote attacker can trigger it by sending crafted requests to the vulnerable API, though the high CVSS attack complexity (AC:H) indicates exploitation requires some difficult-to-meet conditions. Successful exploitation grants administrative privileges, which per HPE leads to complete compromise of the Fabric Composer host. Any organization running Fabric Composer to orchestrate Aruba CX-based network fabrics is potentially affected, particularly if the appliance's API is reachable beyond a restricted management network. There is currently no public proof-of-concept, no known exploitation, no CISA KEV listing, and EPSS is low (0.3% probability of exploitation in 30 days), so near-term risk is limited.
What to do: Track HPE's security advisory (CNA: [email protected]) and upgrade Fabric Composer to the patched release once published, since no fixed version is given in the current data. In the meantime, restrict access to the Fabric Composer API and management interface to trusted management networks and remove any direct internet exposure. Given the high attack complexity, absence of a public PoC, and low EPSS, immediate risk is limited, but internet-exposed or multi-tenant management deployments should be prioritized for patching.
| HPE (Aruba Networks) HPE Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.