ZeroHour

CVE-2026-73713

moderate

Local Privilege Escalation to Root in HPE Aruba Fabric Composer

CVSS 3.1
7.8 high
EPSS
<1%p1
Published
()
Modified
AI analysis

HPE has disclosed local privilege-escalation vulnerabilities (CWE-269, improper privilege management) in HPE Networking Fabric Composer, the Aruba fabric orchestration appliance. An attacker who already has a low-privileged foothold on the system — via a compromised admin account, shell access, or another flaw — can exploit the condition locally without user interaction. Successful exploitation yields arbitrary code execution with root privileges on the underlying operating system of the appliance, giving full control over the orchestration host. Organizations running HPE/Aruba Fabric Composer to orchestrate their data center switching fabrics are affected, though the local attack vector means only parties with access to the appliance's OS are exposed. No public proof-of-concept, no entries in CISA KEV, and a very low EPSS (0.1%, 1st percentile) indicate no known exploitation at this time.

What to do: Check the HPE security bulletin (CNA: [email protected]) for the fixed Fabric Composer release applicable to your deployment and upgrade promptly. Until patched, restrict console/SSH and other local access to the appliance's underlying OS to trusted administrators and limit accounts with low-privileged shell access. Since the flaw is local and unexploited, no emergency action is required, but prioritize patching in the next maintenance window.

Affected
arubanetworks (HPE) Fabric Composer
Estimated exposure
moderatelikely on the order of thousands of appliance deployments worldwide (exact install base unpublished) — HPE/Aruba Fabric Composer is a specialized data-center orchestration appliance deployed per enterprise fabric rather than a mass-market or internet-facing product, and public scan/install counts are not available, so the estimate follows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with root privileges on the underlying operating system of the affected system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.