CVE-2026-73725
nicheLocal Privilege Escalation to Root in HPE Aruba Networking Fabric Composer
CVE-2026-73725 is an improper privilege management flaw (CWE-269) in HPE Aruba Networking Fabric Composer, HPE's orchestration platform for Aruba data center switching. An attacker who already has low-privileged access on the local host can exploit it; the high attack-complexity rating indicates the conditions for success are non-trivial, but no user interaction is required. A successful exploit yields arbitrary code execution with root privileges, meaning a full compromise of the Fabric Composer host. Any organization running Fabric Composer is potentially affected, though the available data does not specify which software versions are vulnerable, so defenders should consult the HPE advisory for affected and fixed releases. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at about 0.1%.
What to do: Check the HPE security advisory for CVE-2026-73725 to identify affected and patched Fabric Composer releases and upgrade promptly. Because exploitation requires local, low-privileged access to the appliance, restrict shell/CLI access to Fabric Composer hosts to trusted administrators and keep the management interface off unrestricted networks. Given the absence of public PoCs or known exploitation, treat this as a routine patching priority rather than an emergency.
| HPE (Aruba) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.