CVE-2026-73719
nicheArbitrary file write in HPE Aruba Networking Fabric Composer API allows admin-to-root RCE
CVE-2026-73719 is an arbitrary file write vulnerability (CWE-73) in the API of HPE Aruba Networking Fabric Composer, the orchestration appliance used to manage HPE Aruba data center switching fabrics. An attacker who already holds administrative credentials on the appliance can send crafted API requests that write files to attacker-chosen paths on the underlying operating system. By placing or overwriting files in privileged locations, the attacker can escalate privileges and execute arbitrary system commands with root rights, giving full control of the host with high confidentiality, integrity, and availability impact. Exploitation requires high privileges (CVSS 3.1 base 7.2, PR:H, network-reachable API), is not known to be exploited in the wild, has no public proof of concept, and carries an EPSS 30-day exploitation probability of about 0.5%. Any organization running HPE Aruba Networking Fabric Composer is potentially affected; the provided data does not include affected or fixed version ranges, so check HPE's advisory for those details.
What to do: Consult HPE's security advisory for CVE-2026-73719 to identify the affected versions and the patched Fabric Composer release, and upgrade as soon as a fix is available. Until then, restrict the Fabric Composer API and management interface to trusted management networks and minimize the number of accounts with administrative privileges, since exploitation requires admin authentication. Review administrative accounts for unusual API activity and avoid shared admin credentials.
| HPE (Aruba) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.