CVE-2026-73722
nicheAuthenticated command injection in HPE Aruba Networking Fabric Composer
CVE-2026-73722 describes command injection vulnerabilities in the web-based management interface of HPE (Aruba) Networking Fabric Composer. An attacker who is already authenticated to the management interface can submit crafted input that is interpreted and run as operating-system commands; per the CVSS vector (PR:H), high-privilege, administrator-level credentials are required. Successful exploitation yields arbitrary command execution as a privileged user on the underlying operating system, effectively giving the attacker full control of the Fabric Composer host and anything it manages. Only organizations running Fabric Composer to manage Aruba networking fabrics are affected. There is currently no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 1% probability of exploitation in the next 30 days (59th percentile), so no in-the-wild exploitation is known.
What to do: Restrict access to the Fabric Composer web management interface to trusted administrative networks and avoid routine use of high-privilege accounts, since exploitation requires authenticated (admin-level) access. Check HPE's Aruba security advisory for this CVE to identify affected and fixed versions and apply the patched Fabric Composer release as soon as it is available. Review management-interface logs for unexpected commands or anomalous activity originating from authenticated admin sessions.
| HPE (Aruba Networks) Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-78, CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.