ZeroHour

CVE-2026-73721

niche

Authenticated SQL Injection in HPE Networking Fabric Composer API

CVSS 3.1
7.2 high
EPSS
<1%p30
Published
()
Modified
AI analysis

HPE Networking Fabric Composer contains SQL injection vulnerabilities (CWE-89) in its API that allow an authenticated remote attacker to send crafted input that is executed against the underlying database of the Fabric Composer instance. The CVSS vector requires high-privileged credentials (PR:H), meaning exploitation needs a valid account with elevated rights rather than any unauthenticated or low-privilege user. A successful attack can read and modify sensitive information in the database and, per HPE, may escalate to complete compromise of the Fabric Composer host. Only organizations running HPE/Aruba Networking Fabric Composer to orchestrate and manage data center networking are affected. There is currently no known exploitation in the wild, no public proof-of-concept, and a low (~0.4%) 30-day exploitation probability per EPSS.

What to do: Apply the fixed release identified in the HPE security bulletin (fixed versions were not specified in this dataset) and restrict access to the Fabric Composer API and management interface to trusted administrative networks. Audit which accounts hold high-privilege credentials, since exploitation requires them, and monitor those accounts for anomalous API activity. Given the potential for full host compromise, include the Fabric Composer appliance in incident-response scope if compromise is suspected.

Affected
HPE (Aruba) Networking Fabric Composer
Estimated exposure
nichelikely low thousands of instances worldwide (niche data center orchestration appliance) — Fabric Composer is a specialized virtual appliance deployed per Aruba data center fabric rather than a mass-market or broadly internet-exposed product, so its installed base is far smaller than HPE's mainstream networking lines.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.