CVE-2026-73723
nichePrivilege Escalation via Authorization Flaw in HPE Aruba Networking Fabric Composer
CVE-2026-73723 is an incorrect-authorization flaw (CWE-863, CWE-269) in the web-based management interface of HPE Aruba Networking Fabric Composer (recorded in vendor data as HPE Networking Fabric Composer, vendor Aruba Networks), in which the interface fails to properly enforce role-based authorization for state-changing actions. It is triggered when an authenticated user holding the low-privilege operator role issues requests through the management interface; network access with valid operator credentials is sufficient, with low attack complexity and no user interaction required. A successful attacker can perform state-changing actions that exceed the operator role's authorization level, producing a high integrity impact and some availability impact; the published CVSS vector indicates no confidentiality impact, so this is not a data-theft or code-execution flaw. Any organization running HPE Aruba Networking Fabric Composer and granting operator-level accounts through the web interface is affected, though affected and fixed version ranges were not specified in the available data. Exploitation status: no public proof-of-concept is known, no in-the-wild exploitation has been reported, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days (28th percentile).
What to do: Upgrade Fabric Composer to the fixed release identified in HPE's security advisory for CVE-2026-73723 (the fixed version is not stated in the available data). Until patched, restrict access to the web management interface to trusted users, review which accounts hold the operator role, and audit recent state-changing actions performed by operator users for unauthorized modifications. Prioritize environments where operator accounts are shared or broadly accessible, since valid operator credentials are the only requirement for exploitation.
| Aruba Networks (HPE) HPE Networking Fabric Composer - web-based management interface | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-863, CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.