ZeroHour

CVE-2026-73722

niche

Authenticated command injection in HPE Aruba Networking Fabric Composer

CVSS 3.1
7.2 high
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-73722 describes command injection vulnerabilities in the web-based management interface of HPE (Aruba) Networking Fabric Composer. An attacker who is already authenticated to the management interface can submit crafted input that is interpreted and run as operating-system commands; per the CVSS vector (PR:H), high-privilege, administrator-level credentials are required. Successful exploitation yields arbitrary command execution as a privileged user on the underlying operating system, effectively giving the attacker full control of the Fabric Composer host and anything it manages. Only organizations running Fabric Composer to manage Aruba networking fabrics are affected. There is currently no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 1% probability of exploitation in the next 30 days (59th percentile), so no in-the-wild exploitation is known.

What to do: Restrict access to the Fabric Composer web management interface to trusted administrative networks and avoid routine use of high-privilege accounts, since exploitation requires authenticated (admin-level) access. Check HPE's Aruba security advisory for this CVE to identify affected and fixed versions and apply the patched Fabric Composer release as soon as it is available. Review management-interface logs for unexpected commands or anomalous activity originating from authenticated admin sessions.

Affected
HPE (Aruba Networks) Fabric Composer
Estimated exposure
nichelikely on the order of hundreds to low thousands of appliance/VM deployments worldwide (no authoritative install counts) — Fabric Composer is an enterprise fabric-management platform deployed once per Aruba data-center environment rather than broadly distributed software, and no public deployment counts are available, so the installed base is plausibly limited…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.