ZeroHour

CVE-2026-73724

niche

Authenticated Privilege Escalation in HPE Aruba Networking Fabric Composer API

CVSS 3.1
7.1 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-73724 describes privilege escalation flaws in the API of HPE Aruba Networking Fabric Composer, a data center fabric orchestration platform, caused by incorrect or insufficient authorization checks (CWE-863, CWE-269). A remote attacker who already holds valid credentials for a low-privilege operator account can issue API requests that change the state of certain system settings that operator-level users should not be able to modify. Successful exploitation yields a high integrity impact (unauthorized changes to settings) and a low availability impact, with no confidentiality impact, since the flaws do not expose data. Any organization running an affected release of Fabric Composer is exposed, with exploitation requiring only network access to the management API and an operator-level account. Exploitation has not been observed: there is no known in-the-wild activity, no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Check the HPE Aruba Networking security advisory for CVE-2026-73724 and upgrade Fabric Composer to the fixed version it specifies, as the available data does not include version numbers. In the meantime, restrict access to the Fabric Composer API to trusted networks and review recent changes to system settings for modifications made by operator-level accounts. Limit operator-level API credentials to users who genuinely need them.

Affected
HPE (Aruba Networks) HPE Aruba Networking Fabric Composer (API)
Estimated exposure
nicheunknown; likely at most low thousands of management-server deployments — Fabric Composer is a specialized enterprise data center fabric orchestration product typically deployed as a single management instance per customer fabric, and no public install-count or internet-exposure scan data is available, so only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-863, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.