CVE-2026-73712
nicheUnauthenticated OS Command Injection in HPE Networking Fabric Composer
CVE-2026-73712 is a command injection flaw (CWE-78/CWE-77) in the API of HPE Networking Fabric Composer that lets an unauthenticated remote attacker run arbitrary commands on the underlying host operating system. Triggering it requires certain preconditions that are outside the attacker's control, which is reflected in the high attack complexity (AC:H) of the 8.1 CVSS score, so exploitation is conditional rather than universally reliable. A successful attack yields arbitrary command execution on the underlying OS with high ratings for confidentiality, integrity, and availability impact, amounting to complete system compromise. Any organization running HPE Aruba Networking Fabric Composer to orchestrate its data center fabric is potentially affected. There is no evidence of exploitation so far: no public proof of concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.
What to do: Consult the HPE security advisory for CVE-2026-73712 and upgrade Fabric Composer to the fixed release it specifies (the source data does not include version details, so do not assume any version is safe or affected). Until patched, restrict the Fabric Composer API to trusted management networks using ACLs or firewall rules and avoid exposing it to the internet. Because exploitation depends on environmental preconditions outside the attacker's control, environments with tightly restricted API access face materially lower risk.
| HPE (Aruba Networks) Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-78, CWE-77
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.