ZeroHour

CVE-2026-76657

niche

Critical Authentication Bypass in HPE Networking Fabric Composer API

CVSS 3.1
10.0 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

HPE Networking Fabric Composer contains an improper authentication flaw (CWE-287) in its API that allows an unauthenticated remote attacker to circumvent existing authentication controls. The weakness is reachable over the network with no privileges and no user interaction required, most plausibly by sending crafted unauthenticated requests to the product's API. A successful attacker gains administrative privileges, which per the CVSS scope change can lead to complete compromise of the Fabric Composer host with high impact to confidentiality, integrity, and availability. Only organizations running HPE (Aruba) Networking Fabric Composer — typically enterprises using it to orchestrate HPE Aruba networking fabrics from data-center management networks — are affected; the exact affected and fixed version ranges were not provided in the source data. Exploitation has not been observed publicly: there is no known proof-of-concept, the issue is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days (36th percentile).

What to do: Upgrade Fabric Composer to the fixed release cited in the HPE security advisory (specific fixed versions were not provided in the source data), prioritizing any host whose API is reachable beyond a trusted management network. Until patched, restrict API access to dedicated management networks or VLANs, and review the host and logs for unexpected administrative accounts or configuration changes. Watch the HPE advisory for updated version, mitigation, and indicator details.

Affected
HPE (Aruba Networks) HPE Networking Fabric Composer
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide, with very few instances internet-exposed — Fabric Composer is a specialized data-center fabric orchestration platform typically deployed as an internal management appliance rather than an internet-facing service, so both install base and external exposure are limited; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.