CVE-2026-73713
moderateLocal Privilege Escalation to Root in HPE Aruba Fabric Composer
HPE has disclosed local privilege-escalation vulnerabilities (CWE-269, improper privilege management) in HPE Networking Fabric Composer, the Aruba fabric orchestration appliance. An attacker who already has a low-privileged foothold on the system — via a compromised admin account, shell access, or another flaw — can exploit the condition locally without user interaction. Successful exploitation yields arbitrary code execution with root privileges on the underlying operating system of the appliance, giving full control over the orchestration host. Organizations running HPE/Aruba Fabric Composer to orchestrate their data center switching fabrics are affected, though the local attack vector means only parties with access to the appliance's OS are exposed. No public proof-of-concept, no entries in CISA KEV, and a very low EPSS (0.1%, 1st percentile) indicate no known exploitation at this time.
What to do: Check the HPE security bulletin (CNA: [email protected]) for the fixed Fabric Composer release applicable to your deployment and upgrade promptly. Until patched, restrict console/SSH and other local access to the appliance's underlying OS to trusted administrators and limit accounts with low-privileged shell access. Since the flaw is local and unexploited, no emergency action is required, but prioritize patching in the next maintenance window.
| arubanetworks (HPE) Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with root privileges on the underlying operating system of the affected system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.