CVE-2026-73720
moderateAuthenticated RCE via insecure file operations in HPE Aruba Fabric Composer API
CVE-2026-73720 is a vulnerability in the API of HPE Aruba Networking Fabric Composer (the HPE Aruba management platform for AOS-CX networking fabrics) in which insecure file operations — attacker-controlled file names or paths (CWE-73) that feed into OS command execution (CWE-78) — can be abused remotely. An attacker needs authenticated access to the API with high privileges (the CVSS 3.1 vector rates Privileges Required as High), and triggers the flaw by supplying crafted file paths or names to affected API operations. Successful exploitation lets the attacker execute arbitrary commands as a privileged user on the underlying operating system hosting the Fabric Composer appliance, with high impact on confidentiality, integrity, and availability. Any organization running HPE Aruba Fabric Composer is potentially affected, though no specific affected or fixed version numbers appear in the available data, so administrators should consult the HPE security advisory. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.
What to do: Upgrade Fabric Composer to a fixed release as directed by the HPE security advisory (fixed version numbers are not included in the available data). Until patched, restrict API access to trusted management networks and audit which accounts hold high-privilege (administrative) API credentials, since exploitation requires them. On the appliance host, check for unexpected processes or commands executed as a privileged user that could indicate exploitation.
| HPE (arubanetworks) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-78, CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.