CVE-2026-73717
Unauthenticated Command Injection in HPE Aruba Networking Fabric Composer
CVE-2026-73717 is a command injection flaw (CWE-78/CWE-77) in the web-based management interface of HPE Networking Fabric Composer, HPE Aruba's platform for orchestrating data-center networking fabrics. An unauthenticated remote attacker can send malicious input to the web interface over the network, but exploitation only succeeds if certain preconditions outside the attacker's control are met, which is reflected in the CVSS vector's high attack complexity (AC:H) and user-interaction requirement (UI:R). When those conditions are satisfied, the attacker can execute arbitrary operating-system commands on the underlying host, potentially leading to complete compromise of the appliance and the network data it manages. Only deployments of HPE Aruba Networking Fabric Composer are affected; other Aruba or HPE products are not implicated by this CVE. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.7% probability of exploitation within 30 days (51st percentile), indicating no known exploitation in the wild.
What to do: Check HPE's security bulletin for CVE-2026-73717 to identify the affected and fixed Fabric Composer releases and upgrade promptly; do not assume this advisory applies to other Aruba products. Until patched, restrict access to the Fabric Composer web-based management interface to trusted management networks or VPNs and monitor the underlying host for unexpected process or command activity. Given the high attack complexity, user-interaction requirement, and low EPSS (~0.7%), patch within normal high-severity maintenance windows rather than as an emergency.
| HPE (Aruba Networks) HPE Networking Fabric Composer (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-78, CWE-77
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.