CVE-2026-76657
nicheCritical Authentication Bypass in HPE Networking Fabric Composer API
HPE Networking Fabric Composer contains an improper authentication flaw (CWE-287) in its API that allows an unauthenticated remote attacker to circumvent existing authentication controls. The weakness is reachable over the network with no privileges and no user interaction required, most plausibly by sending crafted unauthenticated requests to the product's API. A successful attacker gains administrative privileges, which per the CVSS scope change can lead to complete compromise of the Fabric Composer host with high impact to confidentiality, integrity, and availability. Only organizations running HPE (Aruba) Networking Fabric Composer — typically enterprises using it to orchestrate HPE Aruba networking fabrics from data-center management networks — are affected; the exact affected and fixed version ranges were not provided in the source data. Exploitation has not been observed publicly: there is no known proof-of-concept, the issue is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days (36th percentile).
What to do: Upgrade Fabric Composer to the fixed release cited in the HPE security advisory (specific fixed versions were not provided in the source data), prioritizing any host whose API is reachable beyond a trusted management network. Until patched, restrict API access to dedicated management networks or VLANs, and review the host and logs for unexpected administrative accounts or configuration changes. Watch the HPE advisory for updated version, mitigation, and indicator details.
| HPE (Aruba Networks) HPE Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.