ZeroHour

CVE-2026-73720

moderate

Authenticated RCE via insecure file operations in HPE Aruba Fabric Composer API

CVSS 3.1
7.2 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-73720 is a vulnerability in the API of HPE Aruba Networking Fabric Composer (the HPE Aruba management platform for AOS-CX networking fabrics) in which insecure file operations — attacker-controlled file names or paths (CWE-73) that feed into OS command execution (CWE-78) — can be abused remotely. An attacker needs authenticated access to the API with high privileges (the CVSS 3.1 vector rates Privileges Required as High), and triggers the flaw by supplying crafted file paths or names to affected API operations. Successful exploitation lets the attacker execute arbitrary commands as a privileged user on the underlying operating system hosting the Fabric Composer appliance, with high impact on confidentiality, integrity, and availability. Any organization running HPE Aruba Fabric Composer is potentially affected, though no specific affected or fixed version numbers appear in the available data, so administrators should consult the HPE security advisory. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.

What to do: Upgrade Fabric Composer to a fixed release as directed by the HPE security advisory (fixed version numbers are not included in the available data). Until patched, restrict API access to trusted management networks and audit which accounts hold high-privilege (administrative) API credentials, since exploitation requires them. On the appliance host, check for unexpected processes or commands executed as a privileged user that could indicate exploitation.

Affected
HPE (arubanetworks) HPE Aruba Networking Fabric Composer
Estimated exposure
moderatelikely on the order of a few thousand appliance deployments worldwide — Fabric Composer is a specialized virtual-appliance orchestrator deployed per Aruba AOS-CX data center fabric rather than as an internet-scale or mass-market product, and exploitation additionally requires high-privileged authenticated API…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-78, CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.