CVE-2026-73724
nicheAuthenticated Privilege Escalation in HPE Aruba Networking Fabric Composer API
CVE-2026-73724 describes privilege escalation flaws in the API of HPE Aruba Networking Fabric Composer, a data center fabric orchestration platform, caused by incorrect or insufficient authorization checks (CWE-863, CWE-269). A remote attacker who already holds valid credentials for a low-privilege operator account can issue API requests that change the state of certain system settings that operator-level users should not be able to modify. Successful exploitation yields a high integrity impact (unauthorized changes to settings) and a low availability impact, with no confidentiality impact, since the flaws do not expose data. Any organization running an affected release of Fabric Composer is exposed, with exploitation requiring only network access to the management API and an operator-level account. Exploitation has not been observed: there is no known in-the-wild activity, no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Check the HPE Aruba Networking security advisory for CVE-2026-73724 and upgrade Fabric Composer to the fixed version it specifies, as the available data does not include version numbers. In the meantime, restrict access to the Fabric Composer API to trusted networks and review recent changes to system settings for modifications made by operator-level accounts. Limit operator-level API credentials to users who genuinely need them.
| HPE (Aruba Networks) HPE Aruba Networking Fabric Composer (API) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-863, CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.