ZeroHour

CVE-2026-73717

Unauthenticated Command Injection in HPE Aruba Networking Fabric Composer

CVSS 3.1
7.5 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-73717 is a command injection flaw (CWE-78/CWE-77) in the web-based management interface of HPE Networking Fabric Composer, HPE Aruba's platform for orchestrating data-center networking fabrics. An unauthenticated remote attacker can send malicious input to the web interface over the network, but exploitation only succeeds if certain preconditions outside the attacker's control are met, which is reflected in the CVSS vector's high attack complexity (AC:H) and user-interaction requirement (UI:R). When those conditions are satisfied, the attacker can execute arbitrary operating-system commands on the underlying host, potentially leading to complete compromise of the appliance and the network data it manages. Only deployments of HPE Aruba Networking Fabric Composer are affected; other Aruba or HPE products are not implicated by this CVE. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.7% probability of exploitation within 30 days (51st percentile), indicating no known exploitation in the wild.

What to do: Check HPE's security bulletin for CVE-2026-73717 to identify the affected and fixed Fabric Composer releases and upgrade promptly; do not assume this advisory applies to other Aruba products. Until patched, restrict access to the Fabric Composer web-based management interface to trusted management networks or VPNs and monitor the underlying host for unexpected process or command activity. Given the high attack complexity, user-interaction requirement, and low EPSS (~0.7%), patch within normal high-severity maintenance windows rather than as an emergency.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer (web-based management interface)
Estimated exposure
unknown; plausibly hundreds to low thousands of on-premises virtual appliance deployments worldwide — HPE Aruba Networking Fabric Composer is an on-premises management appliance sold to enterprises running HPE Aruba data-center fabric automation, and no public install-base counts or internet-exposure scan data are available, so the scale…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.