ZeroHour

CVE-2026-73716

niche

Unauthenticated OS Command Injection RCE in HPE Networking Fabric Composer

CVSS 3.1
7.5 high
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-73716 is an unauthenticated remote code execution flaw (CWE-78, OS command injection) in the underlying operating system of HPE Networking Fabric Composer. A remote attacker without credentials could run arbitrary commands on the host, but only when certain preconditions outside the attacker's control are met, which is reflected in the high attack complexity and user-interaction requirement of the CVSS 7.5 score. If exploited, the attacker executes commands as a privileged user on the underlying OS, resulting in complete compromise of the Fabric Composer host. Any organization deploying HPE (Aruba) Networking Fabric Composer to orchestrate and manage its Aruba data-center switching fabric is potentially affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.5%, so no active exploitation is currently known.

What to do: Inventory your environment for HPE Networking Fabric Composer instances and check the current version against the official HPE advisory ([email protected] bulletin) to identify fixed releases, then upgrade as soon as a patched version is published. Until patched, limit the Fabric Composer management interface to trusted administrative networks and avoid exposing it to the internet, since the flaw is network-reachable without credentials. Because exploitation depends on preconditions outside the attacker's control (high CVSS complexity), risk is elevated mainly where the management host is broadly reachable.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (one Fabric Composer VM/appliance per customer fabric; no public install-base figures) — Fabric Composer is a niche enterprise data-center management product sold alongside Aruba CX switching, not a mass-distributed or internet-facing consumer service, so the install base is plausibly a few thousand sites at most.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.